Re: Snort question

From: Kath (kath@kathweb.net)
Date: 09/27/01


Message-ID: <001101c146f6$d45dc9e0$82e53181@resnet.sunysb.edu>
From: "Kath" <kath@kathweb.net>
To: "Claudiu Ionescu" <jones@rdsnet.ro>, "Security Basics" <SECURITY-BASICS@SECURITYFOCUS.COM>
Subject: Re: Snort question
Date: Wed, 26 Sep 2001 21:50:47 -0400

I don't believe so, because ipchains/tables works closer to the kernel level
and I think the packet would have to go through the kernel before being able
to go to the snort filters.

If you want to be logging ipchains/tables, add -l to the end to log things
that fit the rule (However, watch out on some rules, as you could get a huge
file to have to go through).

- k

----- Original Message -----
From: "Claudiu Ionescu" <jones@rdsnet.ro>
To: "Security Basics" <SECURITY-BASICS@SECURITYFOCUS.COM>
Sent: Wednesday, September 26, 2001 4:03 AM
Subject: Snort question

> Hi all,
> Premises: a Linux box with two NICs working as a router and packet
filtering
> device (ipchains or iptable) for a small network behind it. Snort
installed on
> it.
> Question: Would packets that are dropped by the filtering rules reach
snort?
> Please explain your answer. Thank you.



Relevant Pages

  • Re: Snort + (OpenBSD or Linux)
    ... Snort + (OpenBSD or Linux) ... on packet analysis. ...
    (Focus-IDS)
  • [NEWS] Snort TCP Stream Reassembly Integer Overflow Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Snort is a very popular open source network intrusion detection system. ... A workaround for this bug is to disable the TCP stream reassembly module. ... packets with the free command line packet creating utility called hping ...
    (Securiteam)
  • [UNIX] Buffer Overflow in Snort RPC Preprocessor
    ... A buffer overflow has been found in the Snort RPC normalization routines ... The first option will alert on any RPC fragmented record it finds. ... current packet length. ...
    (Securiteam)
  • Re: Linux packet drops
    ... Any older libpcap versions have problems on linux and also results in packet loss. ... We are using Snort on Linux in the binary packet capture mode (capture ... 512MB RAM and 72 GB SATA HDD, ... We also found that the drop increases when the I/O is high, ...
    (RedHat)
  • CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability]
    ... Snort TCP Stream Reassembly Integer Overflow Vulnerability ... packets with the free command line packet creating utility called hping ...
    (Focus-IDS)

Quantcast