Bluehost.com Web Hosting $6.95

Re: [Snort-users] Smb output

This is a discussion on Re: [Snort-users] Smb output within the Snort forums, part of the System Security and Security Related category; On Wed, Jul 21, 2004 at 04:55:25PM -0500, Frank Knobbe wrote: > > As I said, looks like ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-22-2004
Michael Sconzo
 
Posts: n/a
Default Re: [Snort-users] Smb output

On Wed, Jul 21, 2004 at 04:55:25PM -0500, Frank Knobbe wrote:
>
> As I said, looks like the output plugin could be optimized where the
> admin supplies not only the IP address but also the NetBIOS name of the
> system to be contacted. All Snort would need to do is populate a UDP
> packet and throw it on the wire (without calling smbclient).


Ok, if you re-wrote smbclient (or at least the part that does the
WinPopUp stuff), then yes, you could probably speed it up. But
then you need to get the NetBIOS name out of something etc ... and
calling the external programs via a script or something in a low
traffic environment doesn't cause any loss, and in a high traffic/alert
environment ... that's a not of WinPopUps. All I know is I'm not
gonna volunteer to rewrite smbclient (I'm not that sadistic) [waits
for holy war to start] :)

Then that gets into duplicating work etc ... but if you or somebody
else does it, I wouldn't complain either, and would probably use it.

-=Mike

>
>
> Regards,
> Frank
>




--
The New Testament offers the basis for modern computer coding theory,
in the form of an affirmation of the binary number system.
But let your communication be Yea, yea; nay, nay: for
whatsoever is more than these cometh of evil.
-- Matthew 5:37


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=4721&alloc_id=10040&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 02:19 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0