[Snort-devel] [Snort-sigs] snort-inline and config detection: search-method

Jason Brvenik jason.brvenik at ...402...
Sat Oct 28 10:26:24 EDT 2006


I've a few questions, the answers to them will help figure out what is
going on. Also moving to -devel as it's a more appropriate forum for
this type of thing.

- How is your test rig set up?
  - Are you testing snort and sending/receiving on the same system?
  - Are you using a pcap or live traffic?

- What are your compile options?

- What is the _actual_ rule? drop "any any -> any any" is invalid, is
this over tcp, udp, icmp, IP?

- What are your results without using the threshold?

Christian Swartzbaugh wrote:
> For several search-methods, including the defaults, snort compiled
> with inline does not drop in certain cases and in other cases does not
> alert. It is not consistent across different search methods either.
> 
> snort 2.6.0.2 (with --enable-inline)
> config detection: search-method ac-std
> (and others)
> 
> drop any any -> any any (msg:"does not drop"; content:"12345";
> threshold: type both, track by_src, limit 3, seconds 30; )
> 
> 
> Different search methods seem to treat dropping all differently, can
> anyone describe what the idea is here and why the different search
> methods are causing problems for inline? or should I visit
> snort-inline mailing lists.
> 
> feofil
> 
> -------------------------------------------------------------------------
> Using Tomcat but need to do more? Need to support web services, security?
> Get stuff done quickly with pre-integrated technology to make your job easier
> Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
> http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
> 

-- 
Jason Brvenik - Sourcefire
PGP: 89C6 DE77 3B32 FC03 A5AE B5DD 11DF 4C8B 0D8E 3383
Key: http://cerberus.sourcefire.com/~jbrvenik/jason.brvenik.pgp.key




More information about the Snort-devel mailing list