BPF not working
James Lay <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Snort version: 2.9.19 GRE (Build 85)
hit
03/25-15:50:34.237265 [**] [1:58723:5] SERVER-OTHER Apache Log4j
logging remote code execution attempt [**] [Classification: Attempted
User Privilege Gain] [Priority: 1] {TCP} x.x.x.x:54969 -> y.y.y.y:80
running snort:
/opt/bin/snort --daq afpacket --daq-mode passive --daq-var
buffer_size_mb=64 -i eth2 -k none -c
/opt/etc/snort/external/external.conf 'not (host <ipaddress> or net
<x.x.x.x/20> )'
Any reason this still fires off, even though the offending host x.x.x.x
is in the x.x.x.x/20 netblock? Thank you.
James
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette