[Snort-users] arpspoof unicast arp request from where?

robin mstubbs at ...842...
Thu Jul 11 14:36:06 EDT 2002


Hello. I upgraded to using snort 1.8.7 on openbsd 3.1 I configured arpspoof
thusly: arpspoof: -unicast
so then it produced some alerts that look like this:
"date-time [**] [112:1:1] unicast ARP request [**]"
well how do I know where that is coming from? Is there a way to get more
information about this like the MAC address and IP address? Is this logged
somewhere?






More information about the Snort-users mailing list