|
Re: reporting false positives...: msg#00139security.ids.snort.sigs
What are you using for an event manager or viewer (ie, ACID/BASE, snortsnarf, demarc, etc) and are you logging to a database or just syslog, etc? If you're using one of the web based managers you'll have a packet dump included in your display. You can generally copy that hex/ascii block and we'll know what you're looking at (include ports and flow info as well) If you're on files only you'll have a file in something like /var/log/snort/<IP> with the offending data. You can send that our way as well. If you know an event is going to happen, or you can manually trigger the false you can use tcpdump at the command line on your sensor. Something like: tcpdump -n -i eth0 -w packet.dump.filename host <victimIP> That'll give you a binary dump that you can send our way as well. This is preferred for larger events that require more context than one packet. That is the short version. This would be a good article for bleedingsnort.com if anyone is interested in expanding on the subject. Thanks Matt Russell Fulton wrote: Hi Folks, ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | reporting false positives...: 00139, Russell Fulton |
|---|---|
| Next by Date: | Re: reporting false positives...: 00139, Jason |
| Previous by Thread: | reporting false positives...i: 00139, Russell Fulton |
| Next by Thread: | Re: reporting false positives...: 00139, Jason |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |