[Snort-users] Need help - TCP Stream5

Matt Olney molney at ...1935...
Thu Apr 8 08:36:17 EDT 2010


What port is your traffic on?
What is the rule you are using?
Can you drop us a PCAP?


On Thu, Apr 8, 2010 at 3:59 AM, Parag Pote <pipsparag at ...131...> wrote:

> Hi All,
> I configured snort latest version on a linux PC and able to get it running.
> When I send UDP,ICMP attack, it is getting detected. I use snot tool for
> this. But TCP are not getting detected. I think it is due to stateful nature
> of stream5 proprocessor. So I created a TCP connection using stream socket
> and send attack data (which I understood after sending TCP attack packet
> using snot).
> So now it establishes the TCP connection and then send malicious data. But
> still I can not see any attacks logged in /var/log/snort/alert file.
> Somebody suggested use hping with data file which contains malicious data.
> Tried but no luck.
> Here I have attached snort.conf for reference. Can somebody help me out?
> Rgds,
> Parag
> ------------------------------------------------------------------------------
> Download Intel® Parallel Studio Eval
> Try the new software tools for yourself. Speed compiling, find bugs
> proactively, and fine-tune applications for parallel performance.
> See why Intel Parallel Studio got high marks during beta.
> http://p.sf.net/sfu/intel-sw-dev
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20100408/bf9ed6e0/attachment.html>

More information about the Snort-users mailing list