|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
RE: [Snort-users] a lot of Loopback traffic being logged.
From: Harry Bloomberg (hbloomb
acconnect.com)
Date: Thu Apr 22 2004 - 13:26:55 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, 22 Apr 2004, Chuck Holley wrote:
> OK, I think im on to something. I do not use the -i option, only -c to look
> at the conf. in the conf I have for "HOME_NET 192.168.10.0/24" and a little
> further down I have "HOME_NET any"
>
We are forcing Snort to listen to one real port only with the -i
option, and we're also seeing a *lot* of packets with a source of
127.0.0.1:80. This was confirmed by one of our network guys who plugged another
packet sniffer into the Snort port. This seems to be real traffic, and
we're baffled by the source.
Harry Bloomberg
-------------------------------------------------------
This SF.net email is sponsored by: The Robotic Monkeys at ThinkGeek
For a limited time only, get FREE Ground shipping on all orders of $35
or more. Hurry up and shop folks, this offer expires April 30th!
http://www.thinkgeek.com/freeshipping/?cpg=12297
_______________________________________________
Snort-users mailing list
Snort-users
lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]