[Snort-users] Smurf/Fraggle

Jacob Martinson jmartinson at ...727...
Fri Nov 3 14:56:50 EST 2000

or more specifically . . . can snort be used to identify a pattern that is
spread across more than one packet?  ie, someone hitting portmap on 10
different machines in a short period of time . . . 


-----Original Message-----
From: Jacob Martinson [mailto:jmartinson at ...727...]
Sent: Friday, November 03, 2000 1:11 PM
To: snort-users (E-mail)
Subject: [Snort-users] Smurf/Fraggle

Can snort be configured to detect when you are getting smurfed (you're the
target, not the amplifer) or hit by fraggle, tfn or similar bandwidth
saturating dos attacks?

Snort-users mailing list
Snort-users at lists.sourceforge.net

More information about the Snort-users mailing list