Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] SSH brute force attack sig |
|---|---|
| Date: | 08 Jul 2005 09:25:21 +1200 |
Jeff Kell <jeff-kell@utc.edu> writes:
Matt Jonkman wrote:True, but we're still not able to use those events to respond or block. Nor can we set different thresholds for different ports or port ranges.And P2P searches drive sfportscan nuts, making it essentially useless here.
On the other hand, we *are* interested in P2P and sfportscan is very useful. Admittedly, I do some post-processing on portscan.log, but it's really only counting the number of times a source IP has appeared - I get paged if the dest. port is consistently 22, 135, 445, etc. sfportscan does have false positives, but after a couple of hundred events, it's usually worth taking a look at - in this environment anyway. cheers, Jamie -- James Riden / j.riden@massey.ac.nz / Systems Security Engineer Information Technology Services, Massey University, NZ. GPG public key available at: http://www.massey.ac.nz/~jriden/ ------------------------------------------------------- This SF.Net email is sponsored by the 'Do More With Dual!' webinar happening July 14 at 8am PDT/11am EDT. We invite you to explore the latest in dual core and dual graphics technology at this free one hour event hosted by HP, AMD, and NVIDIA. To register visit http://www.hp.com/go/dualwebinar _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-sigs] SSH brute force attack sig, Jason Haar |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | Re: [Snort-sigs] SSH brute force attack sig, Jason Haar |
| Next by Thread: | Re: [Snort-sigs] SSH brute force attack sig, bmc |
| Indexes: | [Date] [Thread] [Top] [All Lists] |