Snort 1.9.1 win32 is out!

Quote:DESCRIPTION Snort is an open source network intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks. It can perform protocol analysis and content searching/matching in order to detect a variety of attacks and probes, such as buffer overflows, stealth port ...

Slack Space 1613 This topic was started by ,



data/avatar/default/avatar39.webp

3867 Posts
Location -
Joined 2000-02-04

 
http://www.snort.org/
 

Quote:DESCRIPTION 
Snort is an open source network intrusion detection system, capable of
performing real-time traffic analysis and packet logging on IP networks.
It can perform protocol analysis and content searching/matching in order to
detect a variety of attacks and probes, such as buffer overflows, stealth port
scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more.
Snort uses a flexible rules language to describe traffic that it should collect
or pass, as well as a detection engine that utilizes a modular plugin
architecture. Snort has a real- time alerting capability as well,
incorporating alerting mechanisms for syslog, user specified files, a
UNIX socket, or WinPopup messages to Windows clients using Samba's smbclient.
 
Snort has three primary functional modes. It can be used as a straight
packet sniffer like tcpdump(1), a packet logger (useful for network traffic
debugging, etc), or as a full blown network intrusion detection system.
 
Snort logs packets to many formats, including tcpdump(1) binary format or
Snort's decoded ASCII format to a hierarcical set of directories that are
named based on the IP address of the remote host.
 
Plugins allow the detection and reporting subsystems to be extended. Available
plugins include database or XML logging, small fragment detection, portscan
detection, and HTTP URI normalization, IP defragmentation, TCP stream
reassembly and statistical anomaly detection.
 
 
Be sure to grab the frontend:
 
IDSCENTER
 
http://www.packx.net/packx/html/en/index-en.htm
 
 
 
 
Going to go have some fun now!

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic



data/avatar/default/avatar03.webp

581 Posts
Location -
Joined 2002-04-27
Will it sniff a Wan adapter on windows servers?
 
(Ethereal will not... ARG)