[Snort-users] portscan preprocessor and external net

marco turr marco_syslnx at ...5849...
Tue Nov 29 10:48:01 EST 2005

Matt Kettler <mkettler at ...4108...> ha scritto:
 Generally speaking, you want to do the opposite. You want to ignore your subnet,
and no others.

 We need to detect only home hosts that make portscan to any (compromised hosts) because we have a lot of scanning from external.
 Now, i must subnet all internet address? There is no way to make a !$HOME_NET without writing ALL internet address?

Yahoo! Messenger: chiamate gratuite in tutto il mondo 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20051129/a72cf1db/attachment.html>

More information about the Snort-users mailing list