This is a discussion on RE: [Snort-users] Snort re-setup issues within the Snort forums, part of the System Security and Security Related category; This message is in MIME format. Since your mail reader does not understand this format, some or all of this ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible. ------_=_NextPart_001_01C42CB8.3F3E6A28 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 7bit Hi Greg, Can you put a copy of your snort.conf up to look at. As well try running a tcpdump on your interface (eth0) to see if traffic is being captured. It seems from your email here you are not sure if snort is actually seeing traffic. Shawn Truax Security Specialist Corporate Security 155 University Ave. Toronto, Ontario M5H 3B7 (416)327-1107 -----Original Message----- From: Greg Webster [mailto:greg@intouch.ca] Sent: April 27, 2004 5:53 PM To: snort-users@lists.sourceforge.net Subject: [Snort-users] Snort re-setup issues Heya, Maybe I just need to bounce this off someone for a sanity check...advice would be great. Our old SNORT box completely died, so I was unable to get the config file from there to make this easy. The real problem now is that it's not logging anything coming in. /var/log/snort/alert is empty. Here's some quick facts to hopefully narrow down the solution: - Snort box IP address: 192.168.42.51 on eth0 - eth0 is set to promiscuous mode - Snort is listening to 64.69.xxx.xxx/27 - The log files are created and appropriate permissions are given (/var/log/snort) - I've tried to change Snort to listen to 192.168.42.0/24, and portscanning from another box in that network, but Snort didn't log it. - The box is behind two switches... I haven't seen a solution in my searching...any thoughts on where to go next? Thanks, Greg ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users ------_=_NextPart_001_01C42CB8.3F3E6A28 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Diso-8859-1"> <META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version = 5.5.2656.60"> <TITLE>RE: [Snort-users] Snort re-setup issues</TITLE> </HEAD> <BODY> <P><FONT SIZE=3D2>Hi Greg,</FONT> </P> <P><FONT SIZE=3D2>Can you put a copy of your snort.conf up to look = at. As well try running a tcpdump on your interface (eth0) to see = if traffic is being captured. It seems from your email here you = are not sure if snort is actually seeing traffic.</FONT></P> <P><FONT SIZE=3D2>Shawn Truax</FONT> <BR><FONT SIZE=3D2>Security Specialist</FONT> <BR><FONT SIZE=3D2>Corporate Security</FONT> <BR><FONT SIZE=3D2>155 University Ave.</FONT> <BR><FONT SIZE=3D2>Toronto, Ontario</FONT> <BR><FONT SIZE=3D2>M5H 3B7</FONT> <BR><FONT SIZE=3D2>(416)327-1107</FONT> </P> <BR> <P><FONT SIZE=3D2>-----Original Message-----</FONT> <BR><FONT SIZE=3D2>From: Greg Webster [<A = HREF=3D"mailto:greg@intouch.ca">mailto:greg@intouc h.ca</A>]</FONT> <BR><FONT SIZE=3D2>Sent: April 27, 2004 5:53 PM</FONT> <BR><FONT SIZE=3D2>To: snort-users@lists.sourceforge.net</FONT> <BR><FONT SIZE=3D2>Subject: [Snort-users] Snort re-setup issues</FONT> </P> <BR> <P><FONT SIZE=3D2>Heya,</FONT> </P> <P><FONT SIZE=3D2>Maybe I just need to bounce this off someone for a = sanity check...advice</FONT> <BR><FONT SIZE=3D2>would be great.</FONT> </P> <P><FONT SIZE=3D2>Our old SNORT box completely died, so I was unable to = get the config</FONT> <BR><FONT SIZE=3D2>file from there to make this easy.</FONT> </P> <P><FONT SIZE=3D2>The real problem now is that it's not logging = anything coming in.</FONT> <BR><FONT SIZE=3D2>/var/log/snort/alert is empty.</FONT> </P> <P><FONT SIZE=3D2>Here's some quick facts to hopefully narrow down the = solution:</FONT> <BR><FONT SIZE=3D2>- Snort box IP address: 192.168.42.51 on eth0</FONT> <BR><FONT SIZE=3D2>- eth0 is set to promiscuous mode</FONT> <BR><FONT SIZE=3D2>- Snort is listening to 64.69.xxx.xxx/27</FONT> <BR><FONT SIZE=3D2>- The log files are created and appropriate = permissions are given</FONT> <BR><FONT SIZE=3D2>(/var/log/snort)</FONT> <BR><FONT SIZE=3D2>- I've tried to change Snort to listen to = 192.168.42.0/24, and</FONT> <BR><FONT SIZE=3D2>portscanning from another box in that network, but = Snort didn't log it.</FONT> <BR><FONT SIZE=3D2>- The box is behind two switches...</FONT> </P> <P><FONT SIZE=3D2>I haven't seen a solution in my searching...any = thoughts on where to go</FONT> <BR><FONT SIZE=3D2>next?</FONT> </P> <P><FONT SIZE=3D2>Thanks,</FONT> </P> <P><FONT SIZE=3D2>Greg</FONT> </P> <BR> <P><FONT = SIZE=3D2>-------------------------------------------------------</FONT> <BR><FONT SIZE=3D2>This SF.Net email is sponsored by: Oracle 10g</FONT> <BR><FONT SIZE=3D2>Get certified on the hottest thing ever to hit the = market... Oracle 10g. </FONT> <BR><FONT SIZE=3D2>Take an Oracle 10g class now, and we'll give you the = exam FREE. </FONT> <BR><FONT SIZE=3D2><A = HREF=3D"http://ads.osdn.com/?ad_id=3D3149&alloc_id=3D8166&op=3Dclick" = TARGET=3D"_blank">http://ads.osdn.com/?ad_id=3D3149&al...=3D8166&op=3D= click</A></FONT> <BR><FONT = SIZE=3D2>_________________________________________ ______</FONT> <BR><FONT SIZE=3D2>Snort-users mailing list</FONT> <BR><FONT SIZE=3D2>Snort-users@lists.sourceforge.net</FONT> <BR><FONT SIZE=3D2>Go to this URL to change user options or = unsubscribe:</FONT> <BR><FONT SIZE=3D2><A = HREF=3D"https://lists.sourceforge.net/lists/listinfo/snort-users" = TARGET=3D"_blank">https://lists.sourceforge.net/lists/listinfo/snort-use= rs</A></FONT> <BR><FONT SIZE=3D2>Snort-users list archive:</FONT> <BR><FONT SIZE=3D2><A = HREF=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users" = TARGET=3D"_blank">http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-u= sers</A></FONT> </P> </BODY> </HTML> ------_=_NextPart_001_01C42CB8.3F3E6A28-- ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |