This is a discussion on RE: [Snort-users] Cant see alert for rule within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------=_NextPart_000_0002_01C448A6.B1280EE0 Content-Type: text/plain; charset="us-ascii" ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multi-part message in MIME format.
------=_NextPart_000_0002_01C448A6.B1280EE0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable I pulled out my Linksys switch and put in an old 10/100 5-port workgroup hub. Same problem. =20 Any one have any ideas? =20 thanks -----Original Message----- From: snort-users-admin@lists.sourceforge.net [mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Tom Fulton Sent: Wednesday, June 02, 2004 12:37 PM To: Snort-users@lists.sourceforge.net Subject: [Snort-users] Cant see alert for rule 1)=20 Snort 2.0.6 on linux=20 2)=20 Three pcs:=20 1 2 3=20 w2kPC victim linux attacker linux snort box=20 3)=20 I run:=20 Snort -d -e -v -c /etc/snort/snort.conf (no errors)=20 4)=20 Rule in <file://ftp.rules> ftp.rules is:=20 Alert tcp any any -> any 21 (content: "USER administrator"; msg: "FTP administrator login attempt";)=20 5)=20 When I run: ftp <IPVictim> from linux attacker, I don't get any rules = fired on my snort box.=20 6)=20 I have a Gigabit Linksys 5-port workgroup switch between them all=20 Why am I not able to see the alert?=20 Thanks!=20 ------=_NextPart_000_0002_01C448A6.B1280EE0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; = charset=3Dus-ascii"> <TITLE>Message</TITLE> <META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR></HEAD> <BODY> <DIV><SPAN class=3D438553520-02062004><FONT face=3DArial color=3D#0000ff = size=3D2>I=20 pulled out my Linksys switch and put in an old 10/100 5-port workgroup=20 hub. Same problem.</FONT></SPAN></DIV> <DIV><SPAN class=3D438553520-02062004><FONT face=3DArial color=3D#0000ff = size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D438553520-02062004><FONT face=3DArial color=3D#0000ff = size=3D2>Any=20 one have any ideas?</FONT></SPAN></DIV> <DIV><SPAN class=3D438553520-02062004><FONT face=3DArial color=3D#0000ff = size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D438553520-02062004><FONT face=3DArial color=3D#0000ff = size=3D2>thanks</FONT></SPAN></DIV> <BLOCKQUOTE dir=3Dltr style=3D"MARGIN-RIGHT: 0px"> <DIV></DIV> <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr = align=3Dleft><FONT=20 face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B>=20 snort-users-admin@lists.sourceforge.net=20 [mailto:snort-users-admin@lists.sourceforge.net] <B>On Behalf Of = </B>Tom=20 Fulton<BR><B>Sent:</B> Wednesday, June 02, 2004 12:37 PM<BR><B>To:</B> = Snort-users@lists.sourceforge.net<BR><B>Subject:</B> [Snort-users] = Cant see=20 alert for rule<BR><BR></FONT></DIV><!-- Converted from text/rtf format = --> <P><FONT face=3DArial size=3D2>1)</FONT> <BR><FONT face=3DArial = size=3D2>Snort 2.0.6=20 on linux</FONT> </P><BR> <P><FONT face=3DArial size=3D2>2)</FONT> <BR><FONT face=3DArial = size=3D2>Three=20 pcs:</FONT> <BR><FONT face=3DArial size=3D2> = 1 =20 =20 =20 2 =20 =20 3</FONT> <BR><FONT = face=3DArial=20 size=3D2>w2kPC = victim &n bsp; =20 linux=20 = attacker  = ; =20 linux snort box</FONT> </P><BR> <P><FONT face=3DArial size=3D2>3)</FONT> <BR><FONT face=3DArial = size=3D2>I run:</FONT>=20 <BR><FONT face=3DArial size=3D2>Snort -d -e -v -c=20 /etc/snort/snort.conf (no errors)</FONT> = </P><BR> <P><FONT face=3DArial size=3D2>4)</FONT> <BR><FONT face=3DArial = size=3D2>Rule in=20 </FONT><A href=3D"file://ftp.rules"><U><FONT face=3DArial = color=3D#0000ff=20 size=3D2>ftp.rules</FONT></U></A><FONT face=3DArial size=3D2> = is:</FONT> <BR><FONT=20 face=3DArial size=3D2>Alert tcp any any -> any 21 (content: "USER=20 administrator"; msg: "FTP administrator login attempt";) = </FONT></P><BR> <P><FONT face=3DArial size=3D2>5)</FONT> <BR><FONT face=3DArial = size=3D2>When I run:=20 ftp <IPVictim> from linux attacker, I don’t get any = rules fired on=20 my snort box.</FONT> </P><BR> <P><FONT face=3DArial size=3D2>6)</FONT> <BR><FONT face=3DArial = size=3D2>I have a=20 Gigabit Linksys 5-port workgroup switch between them all</FONT> = </P><BR> <P><FONT face=3DArial size=3D2>Why am I not able to see the = alert?</FONT> </P> <P><FONT face=3DArial size=3D2>Thanks!</FONT> = </P></BLOCKQUOTE></BODY></HTML> ------=_NextPart_000_0002_01C448A6.B1280EE0-- ------------------------------------------------------- This SF.Net email is sponsored by the new InstallShield X. From Windows to Linux, servers to mobile, InstallShield X is the one installation-authoring solution that does it all. Learn more and evaluate today! http://www.installshield.com/Dev2Dev/0504 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |