Re: Problem snort
Dorian ROSSE via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <DB7P193MB03463A5BB3D22EF0F0711D03DADA9@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM> |
Hello, With inline and they two interface you will block the rules set to block, With the mode promiscuous the rules set to block won't be block, I hope your success, Thanks you in advance for your answer, Regards. Dorian Rosse. ________________________________ From: Six Tuur <[email protected]> Sent: Sunday, May 29, 2022 5:10:13 PM To: Dorian ROSSE <[email protected]> Subject: Re: [Snort-users] Problem snort Hello Dorian I did there was a problem with my snort rule it works as a daemon. I have a question correct me if I am wrong. It is afpacket that makes a bridge between the two interfaces. There need to be a bridge between the two interfaces for inline mode, because we work with promiscuous mode that reads the packets to the kernel. Promiscuous mode can only work on 1 interface. I think this is the reason why we need a bridge for inline mode? I hope you can read this and given me a fully understanding of how it works. Thank you very much for helping me out. Greetings from Belgium Tuur Six ________________________________ Van: Dorian ROSSE <[email protected]> Verzonden: zaterdag 28 mei 2022 9:23 Aan: Six Tuur <[email protected]>; Six Tuur via Snort-users <[email protected]> Onderwerp: Re: [Snort-users] Problem snort Hello, Your print screen isn't big but do you happen a problem with snort ? Do you launch a line of command snort wanted ? Do you have 'systemctl enable snort' ? Thanks you in advance for all yours answers, Regards. Dorian Rosse. ________________________________ From: Six Tuur <[email protected]> Sent: Friday, May 27, 2022 11:41:38 PM To: Dorian ROSSE <[email protected]>; Six Tuur via Snort-users <[email protected]> Subject: Re: [Snort-users] Problem snort Hello I succeed to set promiscuous mode on with systemd, but don't with the daemon of snort I have an error with PID. I did't with init.d, but it not always work. Can you check my line. It send the logs, but don't always block my rule. I am testing it with ethernalblue via msfconsole from an attacking machine to a vulnerable machine and snort have to drop the packet in the background as a daemon. [cid:b0623a24-9541-401e-8750-90f3d9e568ee] I hope you can help me? Thank you very much with you effort to help me. Cheers Tuur Six ________________________________ Van: Dorian ROSSE <[email protected]> Verzonden: dinsdag 24 mei 2022 21:59 Aan: Six Tuur <[email protected]>; [email protected] <[email protected]> Onderwerp: Re: [Snort-users] Problem snort Hello, Two spoken : Firstly all card of network beginning by BR are card of network cloud, Secondly if you tried to read your card of network from a computer under Windows you should launch the program cmd after you type 'ipconfig' , I hope your success, Thanks you in advance for your answer, Regards. Dorian Rosse. ________________________________ From: Dorian ROSSE <[email protected]> Sent: Tuesday, May 24, 2022 10:19:29 AM To: Six Tuur <[email protected]>; [email protected] <[email protected]> Subject: Re: [Snort-users] Problem snort If you don't use both good card network you happen this error, I launch this line of command in my folder snort you can take the examples for your problem daq : '''sudo snort -c /usr/local/etc/snort/snort.lua --daq-dir ../libdaq-3.0.7 --daq pcap --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b """ I hope your success, Thanks you in advance for your answer, Regards. Dorian Rosse. ________________________________ From: Six Tuur <[email protected]> Sent: Tuesday, May 24, 2022 10:13:27 AM To: Dorian ROSSE <[email protected]>; [email protected] <[email protected]> Subject: Re: [Snort-users] Problem snort No, I do not. I have twe network cards 1 to go in the other to go out. Is it best to bridge it br0 or to use afpacket to bridge it? Cheers Tuur Six ________________________________ Van: Dorian ROSSE <[email protected]> Verzonden: dinsdag 24 mei 2022 7:36 Aan: Six Tuur <[email protected]>; [email protected] <[email protected]> Onderwerp: Re: [Snort-users] Problem snort Hello, Do you set up the same card of network than you g out the line of command 'ifconfig' ? (You should use the line of command iwconfig for card of network wireless), I hope your success, Thanks you in advance for your answer, Regards. Dorian Rosse. ________________________________ From: Six Tuur <[email protected]> Sent: Tuesday, May 24, 2022 2:15:29 AM To: Dorian ROSSE <[email protected]>; [email protected] <[email protected]> Subject: Re: [Snort-users] Problem snort Here is the screenshot. [cid:5032166c-6a52-4479-8b61-3a81483ce577] Also if you know something about daemon -D optie in snort. Can you provide some info? I'm trying to search how it works Greetings Tuur Six ________________________________ Van: Dorian ROSSE <[email protected]> Verzonden: maandag 23 mei 2022 22:05 Aan: Six Tuur <[email protected]>; [email protected] <[email protected]> Onderwerp: Re: [Snort-users] Problem snort Hello, Can you copy paste your error please? Many error from interface are repaired by openappid, Have a nice evening from the France, Thanks you in advance for your answer, Regards. Dorian Rosse. ________________________________ From: Six Tuur <[email protected]> Sent: Monday, May 23, 2022 9:36:10 PM To: Dorian ROSSE <[email protected]> Subject: Re: [Snort-users] Problem snort Hello, I put all those things like config daq: afpacket, ... in my configuration file. When I reload the service from snort I always get the error for the bridged interfaces but I don't no why? greetings Tuur Six ________________________________ Van: Snort-users <[email protected]> namens Dorian ROSSE via Snort-users <[email protected]> Verzonden: donderdag 7 april 2022 18:21 Aan: [email protected] <[email protected]> Onderwerp: [Snort-users] Problem snort Hello, I have found following documentation for help you I was bad with afpacket you can use inline thus I bring the documentation, I hope your success, Regards. Dorian Rosse. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image.png
(image/png, 4.3 KB) - not displayed
image.png
(image/png, 5.4 KB) - not displayed