|
|||||||||||
|
Re: [Snort-devel] 'established' with Snort 2.x on openbsd
From: Andreas Östling <andreaso(at)it.su.se>
Date: Fri Apr 02 2004 - 02:56:04 EST Trying with a config with only preprocessor stream4/stream4_reassemble and the vrfy root rule on your pcap with ip checksum checks: $ snort -l log/ -c test.conf -r snort-debug.pcap 2>&1|grep ALERTS TCP: 14 (100.000%) ALERTS: 0 And without: $ snort -l log/ -c test.conf -r snort-debug.pcap -k noip 2>&1|grep ALERTS TCP: 14 (100.000%) ALERTS: 1 So maybe the problem is to find out why they have incorrect checksums? /Andreas
On Friday 02 April 2004 07:27, Jon Hart wrote:
This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click Snort-devel mailing list Snort-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-devel Received on Fri Apr 2 03:00:22 2004 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:10 EDT |
||||||||||
|
|||||||||||