LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-13-2003, 02:47 PM   #1
fenriswolf
Member
 
Registered: Jul 2001
Location: Boston
Distribution: Slack, SuSe, Debian
Posts: 30

Rep: Reputation: 15
Snort PROMISC question


Okay, I'm running snort. It starts up at when I boot the box, and if I check /var/log/messages, it says it sets eth0 to promiscuous, like it should. When i do an ifconfig on eth0, it doesnt say Promisc though...any ideas?

I could manually set it to promiscuous, but I dont really think that would solve the problem....

any ideas?
 
Old 02-13-2003, 03:30 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
IIRC it has to do with tools utilizing libpcap vs. the kernels' IOCTL gizmoids, anyway I haven't seen it block Snort functionality.
 
Old 02-13-2003, 03:36 PM   #3
fenriswolf
Member
 
Registered: Jul 2001
Location: Boston
Distribution: Slack, SuSe, Debian
Posts: 30

Original Poster
Rep: Reputation: 15
not sure I 100% understand. Do you mean that Snort sets it to promiscuous, but the kernel (and IOCTL stuff) doesnt really realize this, so its really in promiscuous, but only snort knows this?
 
Old 02-13-2003, 04:01 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Yes. If you do "ifconfig <eth device> -promisc", syslog still will say "kernel: <eth device> Setting promiscuous mode", while actually setting setting it with "ifconfig <eth device> +promisc" will have a different line "kernel: device <eth device> entered promiscuous mode". If you run Snort w/o "-p" it should tell using the "device entered" line, but if you're running Snort with the "-p" option syslog still will say "kernel: <eth device> Setting promiscuous mode" even tho it isn't AFAIK.
 
Old 02-14-2003, 09:49 AM   #5
Darin
Senior Member
 
Registered: Jan 2003
Location: Portland, OR USA
Distribution: Slackware, SLAX, Gentoo, RH/Fedora
Posts: 1,024

Rep: Reputation: 45
Just offhand, what kind of network card is eth0? I know some 3Com cards have hardware that rejects packets that aren't either broadcasts or for the card's MAC. This is a design to speed up networking but makes it impossible to use promiscuous mode.
 
Old 02-20-2003, 12:27 PM   #6
fenriswolf
Member
 
Registered: Jul 2001
Location: Boston
Distribution: Slack, SuSe, Debian
Posts: 30

Original Poster
Rep: Reputation: 15
I think its an HP card. Its an HP netserver, so whatever they use.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
snort install question lnx8 Linux - Software 3 09-21-2004 12:51 PM
Snort Question? bigdogg Linux - Software 1 07-26-2004 07:07 AM
Snort Newbie Question kemplej Linux - Networking 1 05-21-2004 10:34 PM
Snort Newbie Question kemplej Linux - Software 0 05-19-2004 04:03 PM
Promisc mode:Win2k question A-dummy Linux - Networking 3 09-03-2002 10:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration