[Snort-users] Encrypted sessions

Tom Sevy tsevy at ...1701...
Wed Nov 28 04:03:04 EST 2001

We're implementing Alteon (Nortel now) ISD SSL devices.... he he he.....
snort, snort.....

-----Original Message-----
From: Fyodor [mailto:fygrave at ...121...]
Sent: Tuesday, November 27, 2001 10:06 PM
To: Michael Aylor
Cc: 'Erek Adams'; Chr. v. Stuckrad; snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Encrypted sessions

On Tue, Nov 27, 2001 at 04:25:50PM -0600, Michael Aylor wrote:
> That would be neat, if there was a way of telling snort about the
> existance of a private RSA key that it had read access to, so it could
> reverse engineer the public key exchange it was watching...am I
> oversimplifying?  My understanding was that, if you had the private key
> (and presumably the password used to encrypt it), then you'd be able to
> decode any traffic using that key.  Am I incorrect?

yes. see http://www.rtfm.com/ssldump/, the only thing we need to somehow
integrate such huge piece into snort :-)

Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list