[Snort-users] portscan traffic & acid

Baxter, Anthony (ABAXTER) ABAXTER at ...10513...
Fri Nov 7 06:52:17 EST 2003


 Could someone let me know if in the arpspoof_detect_host preprossor line of
snort.conf should I have the two ethernet ports ip and mac addresses or
should I have ip and mac address of other servers on same network ip and mac
addresses.

-----Original Message-----
From: wb
To: snort-users at lists.sourceforge.net
Sent: 11/6/03 1:35 PM
Subject: [Snort-users] portscan traffic & acid

i have snort, mysql & acid running OK. i notice on the acid page that
portscan traffic isn't showing? how do i get this data to show too?
i guess there is an output module for this but i'm not seeing it in my
snort.conf file.



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?   SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list