[Snort-users] Finding rules for internal network
j.riden at ...11179...
Mon Feb 7 13:27:11 EST 2005
sEc nErD <umkcguy1978 at ...131...> writes:
> Hi ALL,
> I am trying to work through a snort box on debian configured by some
> other engineer for the rule sets.
> I have to find why the snort is able to detect outside scans on the
> network but not able to detect inside scans ,for inside scan scanner
> used is Super Scan
> Could anybody tell me where exactly to look for in the rule set
First guess would be to check for "preprocessor portscan-ignorehosts: "
or "preprocessor portscan2-ignorehosts: " in snort.conf.
In fact, I'm far more worried about portscans originating internally,
because that means I've got problems - where as portscans from outside
seems to be the norm these days.
James Riden / j.riden at ...11179... / Systems Security Engineer
Information Technology Services, Massey University, NZ.
GPG public key available at: http://www.massey.ac.nz/~jriden/
More information about the Snort-users