[Snort-users] snort

Dragos Ruiu dr at ...381...
Fri Sep 27 19:50:03 EDT 2002


On September 28, 2002 01:33 am, MADAMANCHI, RAJESH KUMAR wrote:
> hi all,
> im new to snort.., i appreciate if someone can help me with my question...,
>
> i just have some huge tcpdump binary files with me. i need the
> procedure(using snort) to parse these binary files and get the timestamps
> of all the tcp packets with the ACK flag set.
>
> for eg, i want a text file which consists of the timestamp and the 'ID'
> value for all the packets with ACK flag set
>
> later my program is supposed to read these timestamps and process....
>
> please someone reply me abt how to do this
>

(Read Snort Docs and...)
Write a set of snort rules to match the packets you are interested in.
(look at snort man page for command line options and....)
Run snort to and read in the binary files, and to process them - triggering
on the packets your rules specified. Configure snort to output them 
to another binary tcpdump file again which will leave you with
files containing only the packets you want (presumably :-).

cheers,
--dr

-- 
dr at ...381...   pgp: http://dragos.com/kyxpgp
Advance CanSecWest/03 registration available: http://cansecwest.com
"The question of whether computers can think is like the question
  of whether submarines can swim." --Edsger Wybe Dijkstra 1930-2002





More information about the Snort-users mailing list