RE: [Snort-users] Snort re-setup issues

This is a discussion on RE: [Snort-users] Snort re-setup issues within the Snort forums, part of the System Security and Security Related category; This message is in MIME format. Since your mail reader does not understand this format, some or all of this ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 04-28-2004
Truax, Shawn
 
Posts: n/a
Default RE: [Snort-users] Snort re-setup issues

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C42CB8.3F3E6A28
Content-Type: text/plain;
charset=iso-8859-1
Content-Transfer-Encoding: 7bit

Hi Greg,

Can you put a copy of your snort.conf up to look at. As well try running a
tcpdump on your interface (eth0) to see if traffic is being captured. It
seems from your email here you are not sure if snort is actually seeing
traffic.

Shawn Truax
Security Specialist
Corporate Security
155 University Ave.
Toronto, Ontario
M5H 3B7
(416)327-1107


-----Original Message-----
From: Greg Webster [mailto:greg@intouch.ca]
Sent: April 27, 2004 5:53 PM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] Snort re-setup issues


Heya,

Maybe I just need to bounce this off someone for a sanity check...advice
would be great.

Our old SNORT box completely died, so I was unable to get the config
file from there to make this easy.

The real problem now is that it's not logging anything coming in.
/var/log/snort/alert is empty.

Here's some quick facts to hopefully narrow down the solution:
- Snort box IP address: 192.168.42.51 on eth0
- eth0 is set to promiscuous mode
- Snort is listening to 64.69.xxx.xxx/27
- The log files are created and appropriate permissions are given
(/var/log/snort)
- I've tried to change Snort to listen to 192.168.42.0/24, and
portscanning from another box in that network, but Snort didn't log it.
- The box is behind two switches...

I haven't seen a solution in my searching...any thoughts on where to go
next?

Thanks,

Greg


-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g.
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users

------_=_NextPart_001_01C42CB8.3F3E6A28
Content-Type: text/html;
charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2656.60">
<TITLE>RE: [Snort-users] Snort re-setup issues</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2>Hi Greg,</FONT>
</P>

<P><FONT SIZE=3D2>Can you put a copy of your snort.conf up to look =
at.&nbsp; As well try running a tcpdump on your interface (eth0) to see =
if traffic is being captured.&nbsp; It seems from your email here you =
are not sure if snort is actually seeing traffic.</FONT></P>

<P><FONT SIZE=3D2>Shawn Truax</FONT>
<BR><FONT SIZE=3D2>Security Specialist</FONT>
<BR><FONT SIZE=3D2>Corporate Security</FONT>
<BR><FONT SIZE=3D2>155 University Ave.</FONT>
<BR><FONT SIZE=3D2>Toronto, Ontario</FONT>
<BR><FONT SIZE=3D2>M5H 3B7</FONT>
<BR><FONT SIZE=3D2>(416)327-1107</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>-----Original Message-----</FONT>
<BR><FONT SIZE=3D2>From: Greg Webster [<A =
HREF=3D"mailto:greg@intouch.ca">mailto:greg@intouc h.ca</A>]</FONT>
<BR><FONT SIZE=3D2>Sent: April 27, 2004 5:53 PM</FONT>
<BR><FONT SIZE=3D2>To: snort-users@lists.sourceforge.net</FONT>
<BR><FONT SIZE=3D2>Subject: [Snort-users] Snort re-setup issues</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>Heya,</FONT>
</P>

<P><FONT SIZE=3D2>Maybe I just need to bounce this off someone for a =
sanity check...advice</FONT>
<BR><FONT SIZE=3D2>would be great.</FONT>
</P>

<P><FONT SIZE=3D2>Our old SNORT box completely died, so I was unable to =
get the config</FONT>
<BR><FONT SIZE=3D2>file from there to make this easy.</FONT>
</P>

<P><FONT SIZE=3D2>The real problem now is that it's not logging =
anything coming in.</FONT>
<BR><FONT SIZE=3D2>/var/log/snort/alert is empty.</FONT>
</P>

<P><FONT SIZE=3D2>Here's some quick facts to hopefully narrow down the =
solution:</FONT>
<BR><FONT SIZE=3D2>- Snort box IP address: 192.168.42.51 on eth0</FONT>
<BR><FONT SIZE=3D2>- eth0 is set to promiscuous mode</FONT>
<BR><FONT SIZE=3D2>- Snort is listening to 64.69.xxx.xxx/27</FONT>
<BR><FONT SIZE=3D2>- The log files are created and appropriate =
permissions are given</FONT>
<BR><FONT SIZE=3D2>(/var/log/snort)</FONT>
<BR><FONT SIZE=3D2>- I've tried to change Snort to listen to =
192.168.42.0/24, and</FONT>
<BR><FONT SIZE=3D2>portscanning from another box in that network, but =
Snort didn't log it.</FONT>
<BR><FONT SIZE=3D2>- The box is behind two switches...</FONT>
</P>

<P><FONT SIZE=3D2>I haven't seen a solution in my searching...any =
thoughts on where to go</FONT>
<BR><FONT SIZE=3D2>next?</FONT>
</P>

<P><FONT SIZE=3D2>Thanks,</FONT>
</P>

<P><FONT SIZE=3D2>Greg</FONT>
</P>
<BR>

<P><FONT =
SIZE=3D2>-------------------------------------------------------</FONT>
<BR><FONT SIZE=3D2>This SF.Net email is sponsored by: Oracle 10g</FONT>
<BR><FONT SIZE=3D2>Get certified on the hottest thing ever to hit the =
market... Oracle 10g. </FONT>
<BR><FONT SIZE=3D2>Take an Oracle 10g class now, and we'll give you the =
exam FREE. </FONT>
<BR><FONT SIZE=3D2><A =
HREF=3D"http://ads.osdn.com/?ad_id=3D3149&alloc_id=3D8166&op=3Dclick" =
TARGET=3D"_blank">http://ads.osdn.com/?ad_id=3D3149&al...=3D8166&op=3D=
click</A></FONT>
<BR><FONT =
SIZE=3D2>_________________________________________ ______</FONT>
<BR><FONT SIZE=3D2>Snort-users mailing list</FONT>
<BR><FONT SIZE=3D2>Snort-users@lists.sourceforge.net</FONT>
<BR><FONT SIZE=3D2>Go to this URL to change user options or =
unsubscribe:</FONT>
<BR><FONT SIZE=3D2><A =
HREF=3D"https://lists.sourceforge.net/lists/listinfo/snort-users" =
TARGET=3D"_blank">https://lists.sourceforge.net/lists/listinfo/snort-use=
rs</A></FONT>
<BR><FONT SIZE=3D2>Snort-users list archive:</FONT>
<BR><FONT SIZE=3D2><A =
HREF=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users" =
TARGET=3D"_blank">http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-u=
sers</A></FONT>
</P>

</BODY>
</HTML>
------_=_NextPart_001_01C42CB8.3F3E6A28--



-------------------------------------------------------
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g.
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:59 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0