[Snort-users] stealth interface
d_greenjr at ...125...
Tue Apr 8 17:33:12 EDT 2003
I was told the following but have not tried it:
" On NT you just disable all bindings for a network card. I haven´t tried
with snort but it works just fine with other IDS´s."
Let me know if it works.
----- Original Message -----
From: "Tom Culpepper" <tculpepp at ...8819...>
To: <snort-users at lists.sourceforge.net>
Sent: Tuesday, April 08, 2003 8:05 PM
Subject: Re: [Snort-users] stealth interface
> Is something like this possible on a windows system?
> Eric Baur wrote:
> > Some of the other replies seem like too much work... and are
> > harder to maintain (or someone else to figure out if they need to
> > figure out what you did).
> > You should be able to change the ifcfg-eth1 file (or whatever
> > number you want to be ip-less) to be:
> > DEVICE=eth1
> > ONBOOT=yes
> > BOOTPROTO=none
> > That seems to be working in my installation (also RH8.0) without
> > any issues. (Now, my next mystery is seeing if I can find a way to
> > refer to the devices as "lan", "wan" and "dmz" instead of "eth1",
> > "eth2" and "eth3".)
> > Eric
> > d_greenjr wrote:
> >> Can someone tell me or give me the URL on how to create an
> >> interface with no ipaddr (stealth), on a linux [RH8] system? (Not
> >> the receive only cable-I saw that in the snort FAQs) I have
> >> searched the Internet and the snort archives but have not found a
> >> message/page that describes what to do-only the end results.
> This SF.net email is sponsored by: ValueWeb:
> Dedicated Hosting for just $79/mo with 500 GB of bandwidth!
> No other company gives more support or power for your dedicated server
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> Snort-users list archive:
More information about the Snort-users