Snort mailing list archives

Re: Dynamic Preprocessor install (PE Hunter) help


From: "Tim Maletic" <tmaletic () gmail com>
Date: Thu, 28 Aug 2008 12:41:58 -0400

On Thu, Aug 28, 2008 at 12:21 PM, Tommy Cansanay <toortog () gmail com> wrote:
I got it to compile,
run, and I tried testing it on a dedicated network, but haven't had any hits
either. Curious, do you have the preproc name when it did fire?

When pehunter fires, snort will drop log messages like:
PE file extracted: 69120 bytes dumped to
pehunted/388b8fbc36a8558587afc90fb23a3b99.

(Those paying attention will recognize the md5 of notepad.exe.  :)

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: