Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] SYN Proxy |
|---|---|
| Date: | Tue, 19 Jul 2005 18:59:55 -0500 |
Hello:
Regards
Xavier Cabrera.
Will Metcalf wrote:
I could think of a way to do this, it probably wouldn't be very clean and would more than likely require an ip stack to be loaded on your inline box.
This is really something that should be handled in netfilter rather than in snort-inline. If packets make it to the queue and you have a lot of spoofed packets your DoS isn't going to be on the end host your trying to protect, it's going to be your inline box dealing with all the damn context switching between user space and kernel space.
Regards,
Will
On 7/19/05, Matt Kettler <mkettler@evi-inc.com> wrote:
Xavier Cabrera wrote:
Anyone know how snort can work like a Syn Proxy in inline mode?
Not that I'm aware of.. Ultimately I think you'll have to do this in two stages, something like this:
PC -> syn proxy -> snort inline -> Internet
You might be able to wrap it all up on the same box by using two interfaces and have the proxy tool running on the inside interface, and then inline snort on the outside.
Something like this:
inside interface ->syn proxy -> OS routing -> snort inline -> outside interface
but I'm not up-to-speed on all the syn proxy tools out there, or snort's current inline support.
------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] SYN Proxy, Will Metcalf |
|---|---|
| Next by Date: | [Snort-users] Re: Snort-users digest, Vol 1 #5201 - 5 msgs, Nick Plante |
| Previous by Thread: | Re: [Snort-users] SYN Proxy, Will Metcalf |
| Next by Thread: | Re: [Snort-users] SYN Proxy, Matt Kettler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |