[Snort-users] sharesniffer detection

Dr SuSE drsuse at ...748...
Sat Mar 17 03:21:10 EST 2001


A few of us on #Snort tried to come up with something last week but none of use 
could get it to install on any of our machines.

Correct me if I'm wrong, but I would assume the netbios rules already included 
with Snort would be able to detect any Sharesniffer activity.

> Hi all,
> 
> Has anybody make a rule to effectively detect scanning by sharesniffer? Or
> better still, can somebody explain how does this creature really works? Sorry
> if this has been asked before, but I think the mailing list archive need to be
> updated ;-)
> 
> Thanks in advance,
> 
> Cheers,
> Regards
> Shaiful
> 
> ____________________________________________________________________
> Get free email and a permanent address at http://www.netaddress.com/?N=1
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> 




---------------------------------------------
Microsoft ist nicht installiert.
http://www.drsuse.org/






More information about the Snort-users mailing list