[Snort-users] SHUN

ams67 ams67 at ...3655...
Mon Dec 2 22:29:02 EST 2002

-----Original Message-----
>From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users->admin at lists.sourceforge.net] On Behalf Of Alberto
>Sent: Tuesday, 3 December 2002 8:38 p.m.
>Cc: snort-users at lists.sourceforge.net
>Subject: Re: [Snort-users] SHUN
>Maybe I missed something. but what does a white-list of IP's have todo 
>with missing internal attacks?
>Yes, snortsam does active blocking. doesn't mean the engine it uses 
>stops alerting on malicious packets.
>You configure the rules to use with snortsam. YOU have control. Just 
>configure snortsam (which uses snort)
>to listen on the internal interface, or am I just extremly tired?

Perhaps I am the one who is missing something. I do not know snortsam (I
will try it for sure). I thought that a white-list is the list of ip
addresses that snortsam will not block and 'analyze' as snort does when
you put the DNS ip address to avoid false positive. However I am would
like to understand how snortsam can manage a syn flood attack where the
ip source is randomly generate for each packet sent. (e.g. synk4).
Filling up the logs, and blocking hundreds o thousand of random ip
address would not be consider a successful DoS?


More information about the Snort-users mailing list