|
|||||||||||
|
RES: snort- problems
From: Auro Pontes <seguranca(at)dgsfactoring.com.br>
Date: Wed Aug 06 2003 - 14:04:07 EDT
> 1) I was led to believe that Snort can run on one machine and
It is important to gather some other information about your network, ie. Is it switched?
It seems to me that you have a switched network, in which case you probably
will need to
> 2) Last night I had a bunch of alerts pop-up which said
These are false positive. This specific rule listens for the string "uid=0", so even this e-mail will probably trigger it because of this statement. Load up the tcpdump log, and you'll probably see the html source code for the SANS and Snort website referencing to the "uid=0" string. Best regards,
Auro Pontes
Captus Networks - Integrated Intrusion Prevention and Traffic Shaping
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT |
||||||||||
|
|||||||||||