As a follow up to the discussions in the list [0, 1] about Snort seeing traffic, I thought this was interesting.  I was just playing with
NMap's new service detection feature [2] and did a scan as follows:
	From host A, run nmap -A -T4 -F
	Snort is on "snorter" at

I got this syslog alert, note it is ICMP, not TCP/80 or TCP/25 as previously

Dec 20 13:53:08 snorter snort: [1:528:3] BAD TRAFFIC loopback traffic
[Classification: Potentially Bad Traffic] [Priority: 2]: <eth0> {ICMP} ->

I isolated the packet, as follows:

/tmp# snort -Xqvder snort.log.2003-12-20.pcap src
12/20-13:53:08.203033 0:6:29:A2:AB:3F -> FF:FF:FF:FF:FF:FF type:0x800 len:0x3C -> ICMP TTL:39 TOS:0x0 ID:36980 IpLen:20 DgmLen:28
Type:8  Code:0  ID:58555   Seq:35350  ECHO
0x0000: FF FF FF FF FF FF 00 06 29 A2 ED 3E 08 00 45 00  ........)..>..E.
0x0010: 00 1C 90 74 00 00 27 01 60 C3 7F 00 00 01 C0 A8  ...t..'.`.......
0x0020: 63 00 08 00 89 2D E4 BB 8A 16 00 00 00 00 00 00  c....-..........
0x0030: 00 00 00 00 00 00 00 00 00 00 00 00              ............


The only thing not clear is IF this packet actually made it onto the wire, or
if Snort only saw it because it was loopback on the Snort host itself.
Unfortunately I will not have time to pursue this any more at the moment.


[0] http://marc.theaimsgroup.com/?l=snort-users&m=106745650608485&w=2
[1] RHEL 3 (Taroon Beta) sendmail put packets out on the wire with a
src or dst (I forget which) port 25. When I killed sendmail and some other
related service they went away. Presumably that was a bug and is fixed in the
released RHEL 3, but I have not tested that.
[2] http://www.insecure.org/nmap/versionscan.html
