Re: SNORT: MAC Address Alert

From: Brad McGary (bmcgary_at_secondfront.net)
Date: 09/19/03

  • Next message: Jordan Wiens: "Re: SNORT: MAC Address Alert"
    To: "James Williams" <jwilliams@mail.wtamu.edu>, "SF-IDS" <focus-ids@securityfocus.com>
    Date: Fri, 19 Sep 2003 08:54:34 -0500
    
    

    Why don't you setup DHCP reservations for the two MAC addresses and assign
    them specific IPs? Once the users acquire the known IPs you can track their
    activity using Snort and or block traffic at the firewall. I'm assuming
    you're using DHCP.

    ----- Original Message -----
    From: "James Williams" <jwilliams@mail.wtamu.edu>
    To: "SF-IDS" <focus-ids@securityfocus.com>
    Sent: Wednesday, September 17, 2003 10:30 AM
    Subject: SNORT: MAC Address Alert

    > We have been having an issue over the past couple of days where a couple
    > of computers are gaining access to our network and picking arbitrary IP
    > addresses to send SPAM emails. We have the MAC addresses of the
    > suspected computers and know which locations they are coming from, but
    > they do not spend much time in any one location. What I would like to do
    > is setup a box with snort and configure a very specific rule set to have
    > snort text message my mobile phone when it sees these two MAC addresses
    > on our network and possibly from which switch/wap/vlan/etc. Is this
    > possible? If so can somebody give me a couple configuration examples?
    >
    > Thank you,
    >
    > James Williams
    >
    >
    > --------------------------------------------------------------------------
    -
    > Captus Networks IPS 4000
    > Intrusion Prevention and Traffic Shaping Technology to:
    > - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
    > - Automatically Control P2P, IM and Spam Traffic
    > - Precisely Define and Implement Network Security & Performance Policies
    > FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    > http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
    > --------------------------------------------------------------------------
    -
    >
    >

    ---------------------------------------------------------------------------
    Captus Networks IPS 4000
    Intrusion Prevention and Traffic Shaping Technology to:
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Precisely Define and Implement Network Security & Performance Policies
    FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
    ---------------------------------------------------------------------------


  • Next message: Jordan Wiens: "Re: SNORT: MAC Address Alert"

    Relevant Pages

    • Re: SNORT: MAC Address Alert
      ... I suggest to implement a kind of "spam detector" with a script ... Subject: SNORT: MAC Address Alert ... > Captus Networks IPS 4000 ... > Intrusion Prevention and Traffic Shaping Technology to: ...
      (Focus-IDS)
    • Network hardware IPS
      ... reviewer about performance hits inline as i believe this would be an ... IPS has been put in. ... > Captus Networks IPS 4000 ... > Intrusion Prevention and Traffic Shaping Technology to: ...
      (Focus-IDS)
    • Re: 14 octet MACs and security
      ... And many thanks to Tauno for explaining the MAC for me. ... accompanying problem is that I have 2 WAPs at opposite ends of the ... IPs that are on an alert list to email me their activity. ... these connections are timing out. ...
      (comp.os.linux.networking)
    • 3com AP2000 (3CRWE20096A) web-based setup
      ... server running on my machine, set to assign IPs between 192.168.0.2 and ... It isn't listening on any of those IPs. ... server, which seems to be running fine, and how do I find out the MAC ... Adam Short - ajs at orinoco dot homelinux dot org ...
      (comp.os.linux.networking)
    • Re: Wired captive portal pen-test
      ... switch-router so you will not be able to see any ... I saw ARP requests coming from the router and asking for the MAC of several other IPs of the same segment where my laptop was connected ... try connecting your laptop to the phone's RJ45 and do a ...
      (Pen-Test)

  • Quantcast