Search:

Type: Posts; User: henry95; Keyword(s):

Search: Search took 0.03 seconds.

  1. Replies
    18
    Views
    32,978

    I checked my snort.conf and this is what I have...

    I checked my snort.conf and this is what I have for http_inspect_Server



    preprocessor http_inspect: global iis_unicode_map unicode.map 1252
    preprocessor http_inspect_server: server default...
  2. Replies
    18
    Views
    32,978

    ahh ok, I'll tinker more with it.

    ahh ok, I'll tinker more with it.
  3. Replies
    18
    Views
    32,978

    The alert is coming from an outbound connection. ...

    The alert is coming from an outbound connection. So when I visit that site, the alert comes up. But I know the site is legit, and I just filtered out alerts from it.
  4. Replies
    18
    Views
    32,978

    Thx guys.

    Thx guys.
  5. Replies
    18
    Views
    32,978

    I have another question, I get some alerts that...

    I have another question, I get some alerts that say "(http_inspect) OVERSIZE CHUNK ENCODING"
    from my ip going out to port 80.

    Can anyone explain to me what that means? I tried searching on the...
  6. Replies
    18
    Views
    32,978

    Those were the iptables commands I was looking...

    Those were the iptables commands I was looking for in my second question.

    Thanks
  7. Replies
    18
    Views
    32,978

    I did some more investigating today... ...

    I did some more investigating today...

    Iptables is dropping the packets , but Snort reads the packets before IPtables does on the NIC connected to the internet. I guess how the machine is setup,...
  8. Replies
    18
    Views
    32,978

    I'll try that, thanks.

    I'll try that, thanks.
  9. Replies
    18
    Views
    32,978

    Is there a log file I can watch to see what get...

    Is there a log file I can watch to see what get drops?

    under /var/logs or somewhere?

    will tcpdump show them being dropped?
  10. Replies
    18
    Views
    32,978

    Snort IDS Question

    I hope I word this correctly.

    I am running IPcop firewall and I always see a lot of garbage traffic coming from over seas. I see a lot of misc MS-SQL attacks from the same range of IPs. I got...
Results 1 to 10 of 10