Snort mailing list archives
arp_spoof
From: ZdenekChladek_cyber <cyber () dopis cz>
Date: Wed, 10 Oct 2018 11:06:59 +0200
Hello,
Iam using Snort3 with alert_fast.
Often I see in the alert_fast log:
[112:1:1] "(arp_spoof) unicast ARP request" [**] [Priority: 3] {ARP} ->
Is somehow possible get information who is the source of the arp spoof?
Thank You
Regards ZAJDAN
_______________________________________________
Snort-users mailing list
Snort-users () lists snort org
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
snort-users-leave () lists snort org
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Current thread:
- arp_spoof ZdenekChladek_cyber (Oct 10)
