Snort mailing list archives
AW: Can snort be used for single host Intrusion Detection?(A newbie Question)
From: "Sean Wheeler" <s.wheeler () netprotect ch>
Date: Fri, 4 Jul 2003 22:53:41 +0200
Single host as in the host snort is running on ? If that is the case simply do not enable promisc mode, and set EXTERNAL_NET & HOME_NET TO any. That way you see attacks coming at your machine and attacks leaving your machine. regards Sean -----Ursprüngliche Nachricht----- Von: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net]Im Auftrag von Louis Lam Gesendet: Mittwoch, 2. Juli 2003 10:44 An: snort-users () lists sourceforge net Betreff: [Snort-users] Can snort be used for single host Intrusion Detection?(A newbie Question) Hi, The snort configuration file allows users to specify a range of network addresses that it detects activities on. I understand that it is possible to ignore traffic coming from a particular host. Is it possible to configure snort such that it only checks traffic coming into a particular host? ===== Warmest Regards, Louis Lam ________________________________________________________________________ Want to chat instantly with your online friends? Get the FREE Yahoo! Messenger http://uk.messenger.yahoo.com/ ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Can snort be used for single host Intrusion Detection?(A newbie Question) Louis Lam (Jul 02)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) David Alonso De La Vega Tapage (Jul 02)
- rules for P2P programs? Julio E. Gonzalez P. (Jul 02)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Erek Adams (Jul 02)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Louis Lam (Jul 03)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Erek Adams (Jul 03)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Andrew R. Baker (Jul 06)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Louis Lam (Jul 08)
- RE: Can snort be used for single host Intrusion Detection?(A newbie Question) Herb Martin (Jul 08)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) Louis Lam (Jul 03)
- Re: Can snort be used for single host Intrusion Detection?(A newbie Question) David Alonso De La Vega Tapage (Jul 02)
