Snort mailing list archives
Re: Same config, FreeBSD vs OpenBSD, WAY different results
From: "Marc Quibell" <mquibell () fbfs com>
Date: Tue, 14 Oct 2003 08:26:19 -0500
Didn't I just say that? It's actually not very strange at all.
Message: 6 Date: Mon, 13 Oct 2003 21:12:33 -0400 From: Jim Brown <jpb () sixshooter v6 thrupoint net> To: snort-users () lists sourceforge net Subject: Re: [Snort-users] Same config, FreeBSD vs OpenBSD, WAY different
results Jim Brown Wrote:
Strangely, after a sniff fest with tcpdump, it looks like the answer is that the OpenBSD box just gets hits from more systems. Strange to me with what I know about virus propagation anyway. (And yes, these are all [**] ICMP PING CyberKit 2.2 Windows [**] sigs.)
Here are tcpdumps from both systems produced with data captured by tcpdump -w ./out.sysname
<snip>
mquibell wrote:I'll take a shot: The OpenBSD box is getting hit more than the other?
------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US provide better services: Click here: http://sourceforge.net/supporters.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: Same config, FreeBSD vs OpenBSD, WAY different results Marc Quibell (Oct 13)
- <Possible follow-ups>
- Re: Same config, FreeBSD vs OpenBSD, WAY different results Marc Quibell (Oct 14)