Snort mailing list archives

Re: Same config, FreeBSD vs OpenBSD, WAY different results


From: "Marc Quibell" <mquibell () fbfs com>
Date: Tue, 14 Oct 2003 08:26:19 -0500




Didn't I just say that? It's actually not very strange at all.


Message: 6
Date: Mon, 13 Oct 2003 21:12:33 -0400
From: Jim Brown <jpb () sixshooter v6 thrupoint net>
To: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Same config, FreeBSD vs OpenBSD, WAY different
results

Jim Brown Wrote:
Strangely, after a sniff fest with tcpdump, it looks like the
answer is that the OpenBSD box just gets hits from more systems.
Strange to me with what I know about virus propagation anyway.
(And yes, these are all [**] ICMP PING CyberKit 2.2 Windows [**] sigs.)

Here are tcpdumps from both systems produced with
data captured by tcpdump -w ./out.sysname

<snip>





mquibell wrote:
I'll take a shot: The OpenBSD box is getting hit more than the other?








-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: