Re: Snort question

From: J Troy Piper (jtp@dok.org)
Date: 09/27/01


Date: Wed, 26 Sep 2001 21:41:07 -0500
From: J Troy Piper <jtp@dok.org>
To: Security Basics <SECURITY-BASICS@SECURITYFOCUS.COM>
Subject: Re: Snort question
Message-ID: <20010926214107.B20776@dok.org>



attached mail follows:


> Hi all,

> Premises: a Linux box with two NICs working as a router and packet filtering
> device (ipchains or iptable) for a small network behind it. Snort installed on
> it.
> Question: Would packets that are dropped by the filtering rules reach snort?
> Please explain your answer. Thank you.

Answer: No. The netfilter interface ip(tables|chains) uses is located at
the kernel level. Snort reads packets by placing the interface in
'promiscuous' mode to view all the packets the kernel hands it, therefore,
packets that are dropped by filtering with iptables or ipchains will never
make it to the snort process.

---

/************************/ /* J. Troy Piper */ /* <jtp@dok.org> */ /* Ignotum per Ignotius */ /************************/




Relevant Pages

  • Re: unidentified DOS "bad traffic"
    ... I'd do some closer looking at the source machine. ... Do you have an idea of the volume of packets that were coming from this ... A particular host has been completely flooding the network with ... My Snort output on ...
    (Incidents)
  • Re: unidentified DOS bad traffic
    ... large and/or small packets, and sometimes fragmented. ... flooding most gateways, and connects to an IRC channel as you describe. ... A particular host has been completely flooding the network ... My Snort output on this trace was filled with nothing but ...
    (Incidents)
  • RE: Which intrusion detection to use?
    ... > deny access to all unused ports to the world there will be no ... Snort does not care ... while I would get ipfw dropping packets in my logs, ... If you want a good book I'd recommend "Building Internet Firewalls" by ...
    (FreeBSD-Security)
  • RE: Which intrusion detection to use?
    ... >>> I don't know how tight your particular setup is, but if you deny ... Snort does not care about ... >> and while I would get ipfw dropping packets in my logs, ... > From my experience snort will not catch much in this setup. ...
    (FreeBSD-Security)
  • RE: Any ideas?
    ... this time the first two Packets from Snort show the third part of the TCP ... because the attacker allready knows your server ... These are entries from my Snort IDS logs and my firewall logs for the IP ...
    (Security-Basics)

Quantcast