Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RES: snort- problems

From: Auro Pontes <seguranca(at)dgsfactoring.com.br>
Date: Wed Aug 06 2003 - 14:04:07 EDT


Hello there,  

> 1) I was led to believe that Snort can run on one machine and

It is important to gather some other information about your network, ie. Is it switched?

It seems to me that you have a switched network, in which case you probably will need to
assign the "monitor port" to snort.  

> 2) Last night I had a bunch of alerts pop-up which said

These are false positive. This specific rule listens for the string "uid=0", so even this e-mail will probably trigger it because of this statement.

Load up the tcpdump log, and you'll probably see the html source code for the SANS and Snort website referencing to the "uid=0" string.

Best regards,

Do you need help?X

Auro Pontes
DGS Factoring



Captus Networks - Integrated Intrusion Prevention and Traffic Shaping
  • Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
  • Automatically Control P2P, IM and Spam Traffic
  • Ensure Reliable Performance of Mission Critical Applications Precisely Define and Implement Network Security and Performance Policies **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo Visit us at: http://www.captusnetworks.com/ads/31.htm
Received on Wed Aug 6 14:38:58 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:16 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library