[Snort-users] Nice result with snort.

Jan Hugo Prins jhp at ...1226...
Mon Jan 29 16:07:03 EST 2001


On Monday 29 January 2001 21:40, you wrote:
> Was the attacker on the same network segment as the snort box ?
> I could be wrong but I thought it was  impossible to get the HW
> Addr on traditional ethernet if the person was not on the same LAN .
>

Yet he was and the packet I got the IP adres from was a packet without a 
masked IP adres. 

Greetings,
Jan Hugo Prins




More information about the Snort-users mailing list