locking down snort

From: Jose Guevarra (jose_at_iquest.ucsb.edu)
Date: 06/24/04

  • Next message: Allan: "Re: Which Windows OS is Safest"
    To: <security-basics@securityfocus.com>
    Date: Thu, 24 Jun 2004 10:28:43 -0700
    
    

    Hi,

     I have some machines running snort. I'd like to restrict ssh/http and
    other access to them. However, I'm not sure if in doing so, would snort not
    'grab' and analyze traffic hitting those ports. I guess I'm asking

    - if I blocked those ports from the outside world would I still detect say a
    port scan on those ports?

    - Who captures the packets first: Firewall(IPTABLES) or SNORT?

    Thanks,

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Allan: "Re: Which Windows OS is Safest"

    Relevant Pages

    • Re: Why eEye Retina (was MBSA scanner)
      ... Sometimes ports would show as open, ... > Ethical Hacking at the InfoSec Institute. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Pen-Test)
    • Re: Possilbe New Arp DoS - dosprmwin.exe
      ... > show a large number of listening TCP ports. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ... pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: girl in destress!!
      ... proxies on non-standard ports, so any "sniffer" programs, such as ... Snort, will not be able to monitor you. ... I used to run open socks and HTTP proxies on non ... HTTP on 8930, corporate admins never got wise to what was ...
      (comp.security.firewalls)
    • RE: Detecting trojans on random ports with encrypted traffic...
      ... Isn't this similar to what SPADE does in snort? ... >>> Intrusion Detection does not have to rely on signatures ... >>> detect connections from and to ports that you normally ... >>> counting any connections that are normal like virus scanner ...
      (Focus-IDS)
    • RE: looking for tool to find open ports and domains
      ... I am looking for a way to scan for specific ports on all the PC's in our ... to facilitate one-on-one interaction with one of our expert instructors. ... pen testing experience in our state of the art hacking lab. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)