Re: [sentinix-list] SNORT as a Sniffer
Michel Blomgren <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <[email protected]> |
On Monday 15 December 2003 16:05, Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected] wrote: > Hi. > Just a quick one here about SNORT. I was told that snort was configured as > a sniffer. No, I said that Snort is a sniffer with a packet analysis filter (rules-based). It's not configured to burp all network traffic to a log (sentinix default is a MySQL db). If I were to have configured it as a sniffer, most users would fill their harddisks in less than a day. It only logs alerts based on the rules (and the default enabled rules are way too many!), all other traffic is left unlogged. I also said that Snort _can_ log all traffic without problem, if one were so inclined. If you want a regular sniffer, try "iptraf", "ipaudit" or what's wrong with tcpdump? :) > Does it only record traffic as defined in the rule sets or does > it record everything on the wire? Just alerts based on the rules! > I realized that someone was abusing my > Internet link and wanted to see what was happening there. When i checked > the SNORT console i did not see anything too much out of the ordinary. I > used another sniffer ( Sniffer Portable from Network associates) and found > that i was capturing allot more traffic. If you just want to capture some packets (regular network forensics) then you should not use Snort, use those I mentioned above, or try Ethercap or Etherape (neither in SENTINIX yet). If you want to capture all traffic during a, e.g. week and analyze that, then Snort is decent for doing that. > The abuser was using a file > sharing (P2P) application. I modified the snort.conf file to include the > P2P rules and checked the console again but i still did not see evidence of > the abuse with SNORT. Either you have done something wrong or the right rules are not in snort.conf. Read the Snort FAQ and check the Snort mailing list! > The SNORT/Sentinix box is connected to a hub that > comes off the firewall so it should see all outgoing and incoming traffic. > The Sniffer Portable was also placed at the same location when it say all > the traffic. > Any ideas? This sounds like something i should place on the SNORT mailing > list and not the Sentinix! Yes! I am able to answer any questions concerning how SENTINIX is configured and how to use the default config, but I don't have the time to take on support on how every software in SENTINIX works, the maintainers of each respective software do a much better job at this anyhow! Michel