[Snort-users] Packets being alerted with other hosts, but not the localhost with Snort on it

John Byrne jbyrnescu at gmail.com
Mon Sep 10 23:15:25 EDT 2018


Wow, It’s working!

That’s pretty much magic.

Thanks A LOT for the help!

John Byrne

> On Sep 10, 2018, at 6:01 PM, wkitty42 at windstream.net wrote:
> 
> On 09/10/2018 07:43 PM, John Byrne wrote:
>> Yeah…  That didn’t work.  Are you toying with me like all of the hackers on my network?
> 
> 
> what?
> 
> 
>> and what do you mean by t-bird?  I didn’t quite understand that.
> 
> 
> ummm... thunderbird... the mozilla email tool...
> 
> 
>> Here’s my command line, so you can give it to more hackers to know how I’m running my setup so they can do some more damage.  ; )
>> (before your suggestion)
>> snort -c /etc/snort/snort.conf -i eth0 -l /var/log
>> (after your suggestion)
>> snort -k none -c /etc/snort/snort.conf -i eth0 -l /var/log
> 
> 
> it should work there but generally we find it at the end of the command line...
> 
> there's nothing unique about your setup ;)
> 
> 
> -- 
> NOTE: No off-list assistance is given without prior approval.
>       *Please keep mailing list traffic on the list unless*
>       *a signed and pre-paid contract is in effect with us.*



More information about the Snort-users mailing list