OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Snort-users] checksum_mode

From: Bamm Visscher (bamm.visschergmail.com)
Date: Mon Sep 05 2005 - 11:39:58 CDT


The option is most often used in my experience when replaying
previously captured traffic (especially traffic that has been
sanitized) and it's not normally something you need to deal with. See
Richard Bejtlich's post on the subject [0].

Bammkkkk

[0] http://taosecurity.blogspot.com/2005/04/using-snorts-k-option-i-was-looking.html

On 9/5/05, Pablo Nebrera <pablonebreraeneotecnologia.com> wrote:
>
>
> I don't understand this option in the snort configuration file.
> Does it check the checksum for every packet? What is the checksum of a
> packet?
>
> What does this option do exactly??
>
> Thanks
>
>
> Pablo

--
sguil - The Analyst Console for NSM
http://sguil.sf.net

-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users