[Snort-users] Re: snort sees no fragmented attack

Holger.Woehle at ...2701... Holger.Woehle at ...2701...
Mon Aug 12 04:57:03 EDT 2002

> echo "GET /aaaaaaa/aaa/aaaaa/aaaaaaaa/aaaaaaa/bcc/bin/ps" | nc

i forgot to tell you some Version numbers :
I am using Snort 1.8.7 also tested it with 1.9 beta 2 and Linux 2.4.18 Intel
Pentium 4 2GHZ 256 MByte RAM.
The Sensor listens behind a Shomiti Ethernet TAP.
May this be the problem ?
The Sensor only catches the "incoming" traffic. I do not want the answers from
the machines.
Am i wrong with that ? Does snort neeed the outgoing traffic for defrag ?


More information about the Snort-users mailing list