Re: Packet Sniffer for Windows

From: Daniel Crichton (danielc@helio.co.uk)
Date: 12/10/01


From: "Daniel Crichton" <danielc@helio.co.uk>
Date: Mon, 10 Dec 2001 17:29:36 -0000

I personally like Snort (http://www.snort.org) - it's free, runs on just
about everything, can log to files or to a MySQL database, can dump all
application level data or just the packet info, is highly configurable with
rulesets, and can even close connections that match rules you define. The
version I have doesn't come with a GUI to configure it (it's a command line
tool) but I think there might be a couple of third-party ones kicking
around - check the downloads section of the Snort site.

Dan



Relevant Pages

  • Re: High availability design of NIDS
    ... > internal storage, using heartbeat, drdb and some hacks, in high ... What we did was to install two snort sensors with the ... on each of the machines for the MySQL database ... Then we used drbd to do a RAID-1 over ...
    (Focus-IDS)
  • Re: IIS and Snort
    ... Subject: IIS and Snort ... Does anyone have any suggestions for generating email alerts from a unix box ... running snort which sends data to a mysql database. ...
    (Focus-IDS)
  • Re: sidestep
    ... I must have missed the email with the Snort alerts. ... >evade mode, the alert appears in my snort log with the same first 40 ... It's a standard portmapper/rpcbind dump request alright, ... Can you respond to attacks based on attack type, severity, source IP, ...
    (Focus-IDS)
  • RE: Snort/Hogwash help
    ... Subject: Snort/Hogwash help ... Also, I need some rulesets. ... So then perhaps I could run Snort against these rules, set it up to log any ... 'snort -D' with whatever else you use on the command line with a '&' at the ...
    (Security-Basics)
  • Re: MySQl snort logging
    ... The problem was in the script I used to start snort. ... command line option it may override what you have in your configuration ... I meant the permissions that the DB allows to users. ...
    (comp.os.linux.security)