Quote:
Originally Posted by //////
i believe that if snort sees 10.000 syn packets in 60 seconds that rule is triggered.
that looks for syns.
|
But my attack command is: attacker hping3 –c 100 –d 120 -S -w 64 -p 53 -flood victim
which means that i send 100 packets Syn.
So, why the rule also triggered (alerting on snort) while i was just attacking once (100 packets syn only)