Snort mailing list archives
RE: stealth interface
From: "Donnie Green" <d_greenjr () hotmail com>
Date: Wed, 09 Apr 2003 11:56:42 -0400
For some reason, the tap doesn't work with my Cisco Fast Hub.
From: <bmcdowell () coxhealthplans com> To: <snort-users () lists sourceforge net> Subject: RE: [Snort-users] stealth interface Date: Wed, 9 Apr 2003 06:12:10 -0500Just build a tap as per the FAQ. It's far easier: tap on, you're stealth. Tap off, you're on the network.I built mine as a modular end for a normal patch cable - kinda like one of those network 'surge suppressors'.-----Original Message----- From: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net]On Behalf Of d_greenjr Sent: Tuesday, April 08, 2003 7:33 PM To: snort-users () lists sourceforge net Subject: Re: [Snort-users] stealth interface I was told the following but have not tried it: " On NT you just disable all bindings for a network card. I haven´t tried this with snort but it works just fine with other IDS´s." Let me know if it works. ----- Original Message ----- From: "Tom Culpepper" <tculpepp () gmu edu> To: <snort-users () lists sourceforge net> Sent: Tuesday, April 08, 2003 8:05 PM Subject: Re: [Snort-users] stealth interface > Is something like this possible on a windows system? > > > Eric Baur wrote: > > > > > Some of the other replies seem like too much work... and are > > harder to maintain (or someone else to figure out if they need to > > figure out what you did). > > You should be able to change the ifcfg-eth1 file (or whatever > > number you want to be ip-less) to be: > > > > DEVICE=eth1 > > ONBOOT=yes > > BOOTPROTO=none > > > > That seems to be working in my installation (also RH8.0) without > > any issues. (Now, my next mystery is seeing if I can find a way to > > refer to the devices as "lan", "wan" and "dmz" instead of "eth1", > > "eth2" and "eth3".) > > > > Eric > > > > d_greenjr wrote: > > > >> Can someone tell me or give me the URL on how to create an > >> interface with no ipaddr (stealth), on a linux [RH8] system? (Not > >> the receive only cable-I saw that in the snort FAQs) I have > >> searched the Internet and the snort archives but have not found a > >> message/page that describes what to do-only the end results. Thanks > > > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: ValueWeb: > Dedicated Hosting for just $79/mo with 500 GB of bandwidth! > No other company gives more support or power for your dedicated server > http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/ > _______________________________________________ > Snort-users mailing list > Snort-users () lists sourceforge net > Go to this URL to change user options or unsubscribe: > https://lists.sourceforge.net/lists/listinfo/snort-users > Snort-users list archive: > http://www.geocrawler.com/redir-sf.php3?list=snort-users > ------------------------------------------------------- This SF.net email is sponsored by: ValueWeb: Dedicated Hosting for just $79/mo with 500 GB of bandwidth! No other company gives more support or power for your dedicated server http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
_________________________________________________________________The new MSN 8: advanced junk mail protection and 2 months FREE* http://join.msn.com/?page=features/junkmail
-------------------------------------------------------This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger for complex code. Debugging C/C++ programs can leave you feeling lost and disoriented. TotalView can help you find your way. Available on major UNIX and Linux platforms. Try it free. www.etnus.com
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: stealth interface, (continued)
- Re: stealth interface Tom Culpepper (Apr 08)
- Re: stealth interface d_greenjr (Apr 08)
- Re: stealth interface Tom Culpepper (Apr 08)
- Re: stealth interface Keg (Apr 10)
- RE: stealth interface Michael Steele (Apr 08)
- How to set WINDOWS up for a Stealth Interface... Michael Steele (Apr 09)
- Re: How to set WINDOWS up for a Stealth Interface... Ueli Kistler (Apr 09)
- Re: How to set WINDOWS up for a Stealth Interface... snort (Apr 09)
- Re: stealth interface Tom Culpepper (Apr 08)