[Snort-devel] ARPSpoof.

Andrew Steven andtan_sg at ...445...
Mon Feb 16 18:14:04 EST 2004


Hi,
Have found out something strange today. Made snort to do the tcpdump. And at 
the same time made ethereal also to sniff. I found that ethereal has the ARP 
frames for the attacks am generating. Where as the tcpdump shows me only 
ICMP packets for the same attacks. That is why feel like ARP alerts are 
going wrong somewhere.
Regards,
Andrew.

_________________________________________________________________
Find it on the web with MSN Search. http://search.msn.com.sg/





More information about the Snort-devel mailing list