[Snort-users] detecting a sniff application

Kevin Brown Kevin.M.Brown at ...1022...
Tue Jul 9 12:57:03 EDT 2002


If the application is a passive sniffer, then no.  Same reason that snort
can't be directly detected sniffing a network.  By actively scanning a
network you can find NICs that are in promisc mode, but that doesn't tell
you why (ethereal, tcpdump, snort, showeq, some other packet sniffer).

Now it might be able to detect someone intruding on the DSL connection.
Depends what they are doing and if snort has a rule for the behavior.

-----Original Message-----
From: Wissam Halawani
To: snort-users at lists.sourceforge.net
Sent: 7/9/02 12:47 PM
Subject: [Snort-users] detecting a sniff application

Hello,
 
is Snort capable of detecting a sniff application on a network, or an
Internet segment. 
Is it capable of detecting whether someone is intruding or sniffing a
DSL line for an internet user?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020709/449c0085/attachment.html>


More information about the Snort-users mailing list