Snort mailing list archives

Re: How to start and monitor packets on windows


From: "Klein, Jeremie" <jeremie.klein () siemens com>
Date: Thu, 20 Jul 2006 13:39:32 +0200

Hi, 

IMHO, you should add the port 80 for telnet. Web traffic use this port.

Regarding your error when launching Snort , i don't really know ..... Is the service on winxp launched the same way as 
from command line ? 



-----Message d'origine-----
De : snort-users-bounces () lists sourceforge net [mailto:snort-users-bounces () lists sourceforge net] De la part de 
VINAY_SHARMA () advanex co jp
Envoyé : jeudi 20 juillet 2006 10:40
À : snort-users () lists sourceforge net
Objet : [Snort-users] How to start and monitor packets on windows

Hi,

     I am new for snort.i installed wincap,snort 2.x and IDScenter on
windows xp.when i trying to start snort there is fatal error:


on telenet decode arguments:
 port to decode telnet on: 21 23 25 119

Error: c:\snort\rules\attack-responses.rules(11) => unknown
classtype:bad-unknow
fatal error, quiting..


if i try to run sonrt from command line on bin directory with snort -v -i1
it will be start but i can not see any packets transaction when i am
browsing any site.


thanks in advance.




Thanks & regards
**************************************
Vinay Sharma
I I S
Advanex Inc (www.advanex.co.jp)
Fon   : 813-3822-5863
Fax         : 813-5815-7881
Email       : vinay_sharma () advanex co jp



-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys -- and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys -- and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: