Re: IIS and Snort

From: Ian Macdonald (sec-home@dirk.demon.co.uk)
Date: 09/21/01


Message-ID: <005201c1422e$e63ab320$64140a0a@IMACDONALD2>
From: "Ian Macdonald" <sec-home@dirk.demon.co.uk>
To: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>, "'Brian Carvalho'" <brian.carvalho@verizon.net>, <focus-ids@securityfocus.com>
Subject: Re: IIS and Snort
Date: Thu, 20 Sep 2001 19:49:32 -0400

Does anyone have any suggestions for generating email alerts from a unix box
running snort which sends data to a mysql database. I wanted to try acid
which is why I decided to log to a database.

Thanks for you suggestions

Ian
----- Original Message -----
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: "'Brian Carvalho'" <brian.carvalho@verizon.net>;
<focus-ids@securityfocus.com>
Cc: <focus-ms@securityfocus.com>
Sent: Wednesday, September 19, 2001 6:49 PM
Subject: RE: IIS and Snort

> ***Is there any way to send alerts with Snort?
>
> Snort generates an alert.ids file where alerts are written. However, you
> can configure output plug-ins for SQL, syslog, etc. You can pretty much
get
> your alerts any way you want 'em with relatively little effort.
>



Relevant Pages

  • RE: IIS and Snort
    ... Subject: IIS and Snort ... ***Are there specific Snort rulesets for IIS? ... Snort generates an alert.ids file where alerts are written. ...
    (Focus-IDS)
  • Re: High availability design of NIDS
    ... > internal storage, using heartbeat, drdb and some hacks, in high ... What we did was to install two snort sensors with the ... on each of the machines for the MySQL database ... Then we used drbd to do a RAID-1 over ...
    (Focus-IDS)
  • RE: New scanner?
    ... your Snort is likely to see hundreds ... >718 alerts consisting of the following: ... >1 instances of WEB-IIS multiple decode attempt ... >and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: lots of port 0 scannings
    ... You don't say how these alerts were generated, but it looks like Snort, ... Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the ... Training features 6 hand-on courses on May 12-13 taught by professionals. ...
    (Incidents)
  • Re: Snort false positive[Scanned]
    ... I get the exact alerts on the network I administer simply because I haven't ... "tuned" the Snort box to the network environment. ...
    (Focus-IDS)