ul 23 11:26:41 rosnort-udp926309uds snort: OpenPcap() device eth0 network lookup: ^Ieth0: no IPv4 address assigned Jul 23 11:26:41 rosnort-udp926309uds snort: Initializing daemon mode Jul 23 11:26:41 rosnort-udp926309uds snort: PID path stat checked out ok, PID path set to /var/run/ Jul 23 11:26:41 rosnort-udp926309uds snort: Writing PID "32766" to file "/var/run//snort_eth0.pid" Jul 23 11:26:41 rosnort-udp926309uds snort: [*] Frag2 config: Jul 23 11:26:41 rosnort-udp926309uds snort: Fragment timeout: 35 seconds Jul 23 11:26:41 rosnort-udp926309uds snort: Fragment memory cap: 4194304 bytes Jul 23 11:26:41 rosnort-udp926309uds snort: Fragment min_ttl: 3 Jul 23 11:26:41 rosnort-udp926309uds snort: Fragment ttl_limit: 8 Jul 23 11:26:41 rosnort-udp926309uds snort: Fragment Problems: 0 Jul 23 11:26:41 rosnort-udp926309uds snort: State Protection: 0 Jul 23 11:26:41 rosnort-udp926309uds snort: Self preservation threshold: 500 Jul 23 11:26:41 rosnort-udp926309uds snort: Self preservation period: 90 Jul 23 11:26:41 rosnort-udp926309uds snort: Suspend threshold: 1000 Jul 23 11:26:41 rosnort-udp926309uds snort: Suspend period: 30 Jul 23 11:26:41 rosnort-udp926309uds snort: WARNING /etc/snort/snort.conf(239) => Unknown stream4: option: min_ttl Jul 23 11:26:41 rosnort-udp926309uds snort: http_decode arguments: Jul 23 11:26:41 rosnort-udp926309uds snort: Unicode decoding Jul 23 11:26:41 rosnort-udp926309uds snort: IIS alternate Unicode decoding Jul 23 11:26:41 rosnort-udp926309uds snort: IIS double encoding vuln Jul 23 11:26:41 rosnort-udp926309uds snort: Flip backslash to slash Jul 23 11:26:41 rosnort-udp926309uds snort: Include additional whitespace separators Jul 23 11:26:41 rosnort-udp926309uds snort: Ports to decode http on: 80 Jul 23 11:26:41 rosnort-udp926309uds snort: rpc_decode arguments: Jul 23 11:26:41 rosnort-udp926309uds snort: Ports to decode RPC on: 111 32771 Jul 23 11:26:41 rosnort-udp926309uds snort: alert_fragments: INACTIVE Jul 23 11:26:41 rosnort-udp926309uds snort: alert_large_fragments: ACTIVE Jul 23 11:26:41 rosnort-udp926309uds snort: alert_incomplete: ACTIVE Jul 23 11:26:41 rosnort-udp926309uds snort: alert_multiple_requests: ACTIVE Jul 23 11:26:42 rosnort-udp926309uds snort: telnet_decode arguments: Jul 23 11:26:42 rosnort-udp926309uds snort: Ports to decode telnet on: 21 23 25 119 Jul 23 11:26:42 rosnort-udp926309uds snort: Conversation Config: Jul 23 11:26:42 rosnort-udp926309uds snort: KeepStats: 0 Jul 23 11:26:42 rosnort-udp926309uds snort: Conv Count: 65535 Jul 23 11:26:42 rosnort-udp926309uds snort: Timeout : 65 Jul 23 11:26:42 rosnort-udp926309uds snort: Alert Odd?: 0 Jul 23 11:26:42 rosnort-udp926309uds snort: Allowed IP Protocols: Jul 23 11:26:42 rosnort-udp926309uds snort: All Jul 23 11:26:42 rosnort-udp926309uds snort: Jul 23 11:26:42 rosnort-udp926309uds snort: Portscan2 config: Jul 23 11:26:42 rosnort-udp926309uds snort: log: /var/log/snort/scan.log Jul 23 11:26:42 rosnort-udp926309uds snort: scanners_max: 3200 Jul 23 11:26:42 rosnort-udp926309uds snort: targets_max: 5000 Jul 23 11:26:42 rosnort-udp926309uds snort: target_limit: 5 Jul 23 11:26:42 rosnort-udp926309uds snort: port_limit: 20 Jul 23 11:26:42 rosnort-udp926309uds snort: timeout: 60 Jul 23 11:26:43 rosnort-udp926309uds snort: Snort initialization completed successfully