[sentinix-list] SNORT as a Sniffer

Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected]
Newsgroups gmane.linux.sentinix
Message-ID <OF66563E95.C275D4B4-ON05256DFD.0051F304-05256DFD.00529A4D@windalco.com>




Hi.
Just a quick one here about SNORT. I was told that snort was configured as
a sniffer. Does it only record traffic as defined in the rule sets or does
it record everything on the wire? I realized that someone was abusing my
Internet link and wanted to see what was happening there. When i checked
the SNORT console i did not see anything too much out of the ordinary. I
used another sniffer ( Sniffer Portable from Network associates) and found
that i was capturing allot more traffic. The abuser was using a file
sharing (P2P) application. I modified the snort.conf file to include the
P2P rules and checked the console again but i still did not see evidence of
the abuse with SNORT. The SNORT/Sentinix box is connected to a hub that
comes off the firewall so it should see all outgoing and incoming traffic.
The Sniffer Portable was also placed at the same location when it say all
the traffic.
Any ideas? This sounds like something i should place on the SNORT mailing
list and not the Sentinix!





====================================
Marlon Richards
Communications Engineer
West Indies Alumina Company
Kirkvine Works
Jamaica
Tel#:    876-961-7434
Fax#:   876-961-7464
Email:  marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.