Snort mailing list archives
RE: rule that captures every packet
From: "Truax, Shawn (MBS)" <Shawn.Truax () mbs gov on ca>
Date: Tue, 14 Sep 2004 08:56:38 -0400
Hi snort user, You might be already doing this but make sure you have some sort of back end processor for the rules like Mudpit or barnyard running. Depending on your traffic you may get too many alerts and overload the system. If memory serves (and someone else here might know better) but a "shadow box" might be the better way to go and couple the two together. A shadow box will capture every packet and store it for you. I haven't set one up my self but a colleague in the office tells me you can do some custom configurations and alerting with shadow. Hope that helps some for the future. Shawn Truax Sr. Security Specialist Corporate Security 155 University Ave. Toronto, Ontario M5H 3B7 (416)327-1107 -----Original Message----- From: Matt Kettler [mailto:mkettler () evi-inc com] Sent: September 13, 2004 7:25 PM To: snort user Cc: snort-users () lists sourceforge net Subject: Re: [Snort-users] rule that captures every packet At 04:59 PM 9/13/2004, snort user wrote:
i want to write a rule that captures every packet. i want to use this to enter the code where pattern matching is done in the function CheckANDPatternMatch. Any help would be appreciated.
alert ip any any -> any any ------------------------------------------------------- This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 Project Admins to receive an Apple iPod Mini FREE for your judgement on who ports your project to Linux PPC the best. Sponsored by IBM. Deadline: Sept. 13. Go here: http://sf.net/ppc_contest.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- rule that captures every packet snort user (Sep 13)
- Re: rule that captures every packet Matt Kettler (Sep 13)
- Re: rule that captures every packet Martin Roesch (Sep 14)
- <Possible follow-ups>
- RE: rule that captures every packet Truax, Shawn (MBS) (Sep 14)
- Re: rule that captures every packet Matt Kettler (Sep 13)