Drooping Spoofed Packets

Ameen Al-Azzawi via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CABcvXqL0HBbPhxzHP9u2xE0ZMy_H9Gao8dxucg6SkC6TiTO+Vg@mail.gmail.com>
Hi everyone,

I have attached a pic of my topology (hopefully it goes through this
mailing list).
The topology represents a DS-Lite technology basic structure.
IPIP6 tunnel has been built between B4 & AFTR machines.

I have an attacking scenario and want to mitigate it.
I am sending (through my attacker machine)  a crafted packet of IPv4 in
IPv6 packet while spoofing the IP address of the B4 router
(2001:db8:0:1::2).
The target is AFTR ens34 interface.

I have installed and configured snort to work in INLINE mode on AFTR
machine.

The question is: what kind of rule should I use?
Is it even possible with SNORT ??



Regards
Ameen

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
Attack.png (image/png, 72 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.