[Snort-users] Smurf/Fraggle

Chris Green cmg at ...671...
Mon Nov 6 17:36:53 EST 2000


Jacob Martinson <jmartinson at ...727...> writes:

> or more specifically . . . can snort be used to identify a pattern that is
> spread across more than one packet?  ie, someone hitting portmap on 10
> different machines in a short period of time . . . 
> 
> -jacob

I don't believe it can out of the box.  This type of thing requires a
preprocessor plugin.

-- 
Chris Green <cmg at ...671...>
Life is a series of rude awakenings.
                -- R.V. Winkle



More information about the Snort-users mailing list