Snort mailing list archives

RE: how to convert payload data from MySQL data table to tcpdump formated data?


From: "samwun" <samwun () hgcbroadband com>
Date: Fri, 24 Oct 2003 09:28:04 +0800

I found where to enable the tcpdump output module. Thanks.

-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net] On Behalf Of Jeff Dell
Sent: Friday, October 24, 2003 1:36 AM
To: 'samwun'
Cc: 'snort-users mailinglist'
Subject: RE: [Snort-users] how to convert payload data from MySQL data
table to tcpdump formated data?

No need to rebuild a packet.. Try Adding the tcpdump output module to
your config.

output log_tcpdump: snort.log

Will put all log events to a tcpdump file snort.log.

Jeff


Aw! I just discovered that the logged data is NOT the entire packet,
just
the protocol data payload. Damn!

Is there some way to rebuild the entire packet from the data logged to
ACID?







-------------------------------------------------------
This SF.net email is sponsored by: The SF.net Donation Program.
Do you like what SourceForge.net is doing for the Open
Source Community?  Make a contribution, and help us add new
features and functionality. Click here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



-------------------------------------------------------
This SF.net email is sponsored by: The SF.net Donation Program.
Do you like what SourceForge.net is doing for the Open
Source Community?  Make a contribution, and help us add new
features and functionality. Click here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: