LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-30-2013, 12:21 PM   #1
NewFedoraUser5
LQ Newbie
 
Registered: Nov 2013
Posts: 7

Rep: Reputation: Disabled
snort don't log port scans


i use nmap to test snort
but snort only work when i make this command

nmap -sV 192.168.1.1 the alert that i get is :

[**] [1:1418:11] SNMP request tcp [**]
[Classification: Attempted Information Leak] [Priority: 2]
11/30-20:18:47.117426 192.168.1.55:58833 -> 192.168.1.1:179
TCP TTL:51 TOS:0x0 ID:64659 IpLen:20 DgmLen:44


if you look at the port from 192.168.1.55 is port is 58833 only heigh ports who come from my pc are record as alert;

when i made commands like -sT and -sY he dint record nothing

how i can configure my snort.conf that will recorded ports scans ?
 
Old 12-01-2013, 02:41 AM   #2
NewFedoraUser5
LQ Newbie
 
Registered: Nov 2013
Posts: 7

Original Poster
Rep: Reputation: Disabled
it seems like some rules work and somenot if i do ping test : ping 192.168.1.1
it make alert

but not for nmap scans

i did this
# preprocessor sfportscan: proto { all } memcap { 10000000 } sense_level { high } scan_type { all } logfile { /var/log/snort/alert }


but still nothing work
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Snort don't want log to mysql lcat Slackware 1 03-07-2005 07:20 AM
snort not logging port scans? Should I use log or alert? lucastic Linux - Security 3 08-30-2004 04:34 AM
Snort, FIN Scans, and port 6346 (Gnutella) green_dragon37 Linux - Security 2 11-17-2003 08:52 AM
Port scans!!! tarballedtux Linux - Security 4 10-29-2002 07:18 AM
Port scans KevStA Linux - Networking 2 05-27-2002 05:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration