Re: Problem snort

Dorian ROSSE via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <DB7P193MB03463A5BB3D22EF0F0711D03DADA9@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM>
Hello,


With inline and they two interface you will block the rules set to block,

With the mode promiscuous the rules set to block won't be block,

I hope your success,

Thanks you in advance for your answer,

Regards.


Dorian Rosse.
________________________________
From: Six Tuur <[email protected]>
Sent: Sunday, May 29, 2022 5:10:13 PM
To: Dorian ROSSE <[email protected]>
Subject: Re: [Snort-users] Problem snort

Hello Dorian

I did there was a problem with my snort rule it works as a daemon. I have a question correct me if I am wrong. It is afpacket that makes a bridge between the two interfaces. There need to be a bridge between the two interfaces for inline mode, because we work with promiscuous mode that reads the packets to the kernel. Promiscuous mode can only work on 1 interface. I think this is the reason why we need a bridge for inline mode? I hope you can read this and given me a fully understanding of how it works. Thank you very much for helping me out. Greetings from Belgium
Tuur Six

________________________________
Van: Dorian ROSSE <[email protected]>
Verzonden: zaterdag 28 mei 2022 9:23
Aan: Six Tuur <[email protected]>; Six Tuur via Snort-users <[email protected]>
Onderwerp: Re: [Snort-users] Problem snort

Hello,


Your print screen isn't big but do you happen a problem with snort ?

Do you launch a line of command snort wanted ?

Do you have 'systemctl enable snort' ?

Thanks you in advance for all yours answers,

Regards.


Dorian Rosse.
________________________________
From: Six Tuur <[email protected]>
Sent: Friday, May 27, 2022 11:41:38 PM
To: Dorian ROSSE <[email protected]>; Six Tuur via Snort-users <[email protected]>
Subject: Re: [Snort-users] Problem snort

Hello

I succeed to set promiscuous mode on with systemd, but don't with the daemon of snort I have an error with PID. I did't with init.d, but it not always work. Can you check my line.  It send the logs, but don't always block my rule. I am testing it with ethernalblue via msfconsole from an attacking machine to a vulnerable machine and snort have to drop the packet in the background as a daemon.
[cid:b0623a24-9541-401e-8750-90f3d9e568ee]
I hope you can help me? Thank you very much with you effort to help me.

Cheers Tuur Six
________________________________
Van: Dorian ROSSE <[email protected]>
Verzonden: dinsdag 24 mei 2022 21:59
Aan: Six Tuur <[email protected]>; [email protected] <[email protected]>
Onderwerp: Re: [Snort-users] Problem snort

Hello,


Two spoken :

Firstly all card of network beginning by BR are card of network cloud,

Secondly if you tried to read your card of network from a computer under Windows you should launch the program cmd after you type 'ipconfig'  ,

I hope your success,

Thanks you in advance for your answer,

Regards.


Dorian Rosse.
________________________________
From: Dorian ROSSE <[email protected]>
Sent: Tuesday, May 24, 2022 10:19:29 AM
To: Six Tuur <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] Problem snort

If you don't use both good card network you happen this error,

I launch this line of command in my folder snort you can take the examples for your problem daq :

'''sudo snort -c /usr/local/etc/snort/snort.lua --daq-dir ../libdaq-3.0.7 --daq pcap --daq dump --daq-var lb_total=4 --daq-var fanout_type=hash -s 65535 -k all -l /var/log/snort -i enp0s25 --daq-var lb_id=1 -i wlp3s0 --daq-var lb_id=2 -z 2 -m 0x1b """

I hope your success,

Thanks you in advance for your answer,

Regards.


Dorian Rosse.
________________________________
From: Six Tuur <[email protected]>
Sent: Tuesday, May 24, 2022 10:13:27 AM
To: Dorian ROSSE <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] Problem snort

No, I do not.
I have twe network cards 1 to go in the other to go out. Is it best to bridge it br0 or to use afpacket to bridge it?
Cheers Tuur Six
________________________________
Van: Dorian ROSSE <[email protected]>
Verzonden: dinsdag 24 mei 2022 7:36
Aan: Six Tuur <[email protected]>; [email protected] <[email protected]>
Onderwerp: Re: [Snort-users] Problem snort

Hello,


Do you set up the same card of network than you g out the line of command 'ifconfig' ? (You should use the line of command iwconfig for card of network wireless),

I hope your success,

Thanks you in advance for your answer,

Regards.


Dorian Rosse.
________________________________
From: Six Tuur <[email protected]>
Sent: Tuesday, May 24, 2022 2:15:29 AM
To: Dorian ROSSE <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] Problem snort

Here is the screenshot.
[cid:5032166c-6a52-4479-8b61-3a81483ce577]
Also if you know something about daemon -D optie in snort. Can you provide some info? I'm trying to search how it works

Greetings Tuur Six
________________________________
Van: Dorian ROSSE <[email protected]>
Verzonden: maandag 23 mei 2022 22:05
Aan: Six Tuur <[email protected]>; [email protected] <[email protected]>
Onderwerp: Re: [Snort-users] Problem snort

Hello,


Can you copy paste your error please?

Many error from interface are repaired by openappid,

Have a nice evening from the France,

Thanks you in advance for your answer,

Regards.


Dorian Rosse.
________________________________
From: Six Tuur <[email protected]>
Sent: Monday, May 23, 2022 9:36:10 PM
To: Dorian ROSSE <[email protected]>
Subject: Re: [Snort-users] Problem snort

Hello,

I put all those things like config daq: afpacket, ... in my configuration file. When I reload the service from snort I always get the error for the bridged interfaces but I don't no why?

greetings
Tuur Six

________________________________
Van: Snort-users <[email protected]> namens Dorian ROSSE via Snort-users <[email protected]>
Verzonden: donderdag 7 april 2022 18:21
Aan: [email protected] <[email protected]>
Onderwerp: [Snort-users] Problem snort

Hello,


I have found following documentation for help you I was bad with afpacket you can use inline thus I bring the documentation,

I hope your success,

Regards.


Dorian Rosse.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image.png (image/png, 4.3 KB) - not displayed
image.png (image/png, 5.4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.