[Snort-users] Finding rules for internal network

James Riden j.riden at ...11179...
Mon Feb 7 13:27:11 EST 2005


sEc nErD <umkcguy1978 at ...131...> writes:

>    Hi ALL,
>
>    I am trying to work through a snort box on debian configured by some
>    other engineer for the rule sets.
>
>    I have to find why the snort is able to detect outside scans on the
>    network but not able to detect inside scans ,for inside scan scanner
>    used is Super Scan
>
>
>
>    Could anybody tell me where exactly to look for in the rule set
>    snort.conf?

First guess would be to check for  "preprocessor portscan-ignorehosts: "
or "preprocessor portscan2-ignorehosts: " in snort.conf.

In fact, I'm far more worried about portscans originating internally,
because that means I've got problems - where as portscans from outside
seems to be the norm these days.

cheers,
 Jamie
-- 
James Riden / j.riden at ...11179... / Systems Security Engineer
Information Technology Services, Massey University, NZ.
GPG public key available at: http://www.massey.ac.nz/~jriden/






More information about the Snort-users mailing list