[Snort-users] Intrusion Detection with Snort

Martin Roesch roesch at ...421...
Thu Oct 5 14:30:49 EDT 2000


Did you compile in SMB alert support?  Did you configure the SMB alert
functionality in the rules file or only from the command line?  Is smbclient
in your $PATH?

     -Marty

Nuno Miguel Neves wrote:
> 
> Hi.
> 
> I'm using snort-1.6.3-patch2.
> 
> What is the correct command line to make snort act as an intrusion detector.
> 
> I ran with "snort -d -l /var/log/snort -M machines -c snort-lib" and then
> from another subnet, I did a nmap -sT -O host, but snort didn't give any
> alert! :-(
> 
> I've already changed the HOME_NET variable to my network (It is not a class
> C network, it's a /27 subnetwork, does that has anything to do?).
> 
> Thanks for any answer, since I'm getting desperate...
> --
>                   nneves at ...351...    Dept. Informatica, Fac. Ciencias,
> |\ |    |\ |      Tel: +351 21 7500528  Univ. Lisboa, Bloco C5, Campo Grande
> | \|uno | \|eves  Fax: +351 21 7500084  1700 Lisboa, Portugal
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users

-- 
Martin Roesch
roesch at ...421...
http://www.snort.org




More information about the Snort-users mailing list