[Snort-users] a lot of Loopback traffic being logged.

Harry Bloomberg hbloomb at ...11694...
Thu Apr 22 11:28:00 EDT 2004


On Thu, 22 Apr 2004, Chuck Holley wrote:

> OK, I think im on to something.  I do not use the -i option, only -c to look
> at the conf.  in the conf I have for "HOME_NET 192.168.10.0/24" and a little
> further down I have "HOME_NET any"
>
   We are forcing Snort to listen to one real port only with the -i
option, and we're also seeing a *lot* of packets with a source of
127.0.0.1:80.  This was confirmed by one of our network guys who plugged another
packet sniffer into the Snort port.  This seems to be real traffic, and
we're baffled by the source.

Harry Bloomberg





More information about the Snort-users mailing list