[Snort-users] Snort URL logging

Rich Stryker rstryker at ...7794...
Tue Jan 14 09:00:12 EST 2003

Does URLSnarf work with W2K machines?

-----Original Message-----
From: Erek Adams [mailto:erek at ...950...]
Sent: Tuesday, January 14, 2003 9:30 AM
To: ALMEIDA Antonio Jose
Cc: 'snort-users at lists.sourceforge.net'
Subject: RE: [Snort-users] Snort URL logging

On Tue, 14 Jan 2003, ALMEIDA Antonio Jose wrote:

> But with urlsnarf i can't filter the source ip, and i really need that. It's
> impossible to do this with Snort?

Impossible?  No.  Waste of time?  Yes.

Use Snort or Tcpdump to snag all traffic, and use a BPF filter to exclude
what you want.  Then replay that file into urlsnarf.

And just a handy little tip:  Never ask your boss why he was surfing
http://www.flashyourrack.com/ .  That would be a careerlimiting move.  ;-)

Erek Adams

   "When things get weird, the wierd turn pro."   H.S. Thompson

This SF.NET email is sponsored by: FREE  SSL Guide from Thawte
are you planning your Web Server Security? Click here to get a FREE
Thawte SSL guide and find the answers to all your  SSL security issues.
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list