[Snort-sigs] Triggering a complex snort rule (packet forging)

Jamie Riden jamie.riden at ...2420...
Tue Apr 2 08:49:03 EDT 2013


Sorry, I'm talking rubbish. The firewall will stop you from the outside as
it's not part of an established connection.



On 2 April 2013 13:47, Asiri Rathnayake <asiri.rathnayake at ...2420...> wrote:

> Hi,
>
>
> On Tue, Apr 2, 2013 at 1:31 PM, Jamie Riden <jamie.riden at ...2420...> wrote:
>
>> You could look at grabbing a real packet and using tcpreplay maybe?
>>
>
> So, grab the packet from within the local network and then try to inject
> it into the network (replay) from outside?
>
> Sounds like a good idea, will give it a go.
>
> Thanks!
>
> - Asiri
>



-- 
Jamie Riden / jamie at ...3509... / jamie.riden at ...2420...
http://uk.linkedin.com/in/jamieriden
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20130402/c0310734/attachment.html>


More information about the Snort-sigs mailing list