Snort mailing list archives

RE: rule that captures every packet


From: "Truax, Shawn (MBS)" <Shawn.Truax () mbs gov on ca>
Date: Tue, 14 Sep 2004 08:56:38 -0400

Hi snort user,

You might be already doing this but make sure you have some sort of back end
processor for the rules like Mudpit or barnyard running.  Depending on your
traffic you may get too many alerts and overload the system.  If memory
serves (and someone else here might know better) but a "shadow box" might be
the better way to go and couple the two together.  A shadow box will capture
every packet and store it for you.  I haven't set one up my self but a
colleague in the office tells me you can do some custom configurations and
alerting with shadow.  Hope that helps some for the future.

Shawn Truax
Sr. Security Specialist
Corporate Security
155 University Ave.
Toronto, Ontario
M5H 3B7
(416)327-1107


-----Original Message-----
From: Matt Kettler [mailto:mkettler () evi-inc com]
Sent: September 13, 2004 7:25 PM
To: snort user
Cc: snort-users () lists sourceforge net
Subject: Re: [Snort-users] rule that captures every packet


At 04:59 PM 9/13/2004, snort user wrote:
i want to write a rule that captures every packet. i want to use this to 
enter the code where pattern matching is done in the function 
CheckANDPatternMatch. Any help would be appreciated.

alert ip any any -> any any



-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM. 
Deadline: Sept. 13. Go here: http://sf.net/ppc_contest.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: