Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] Snort vs. gcc 4.1.0 |
|---|---|
| Date: | Tue, 04 Apr 2006 13:00:02 -0400 |
Snort and gcc 4.1.0 don't get along.
if(csum)
{
p->csum_flags |= CSE_TCP;
! DEBUG_WRAP(DebugMessage(DEBUG_DECODE,
! "Bad TCP checksum 0x%x versus 0x%x\n", csum,
ntohs(p->tcph->th_sum)););
if(InlineMode())
{snort xxxxxxx | grep in_cksum_tcp | sort | uniq -c
Output: 21934 decode.c:2539: TCP in_cksum_tcp is 0x0
Then compile (FC5 again) with gcc 4.1 and -O2. Run with DEBUG_DECODE. Output:
873 decode.c:2539: TCP in_cksum_tcp is 0x0
10110 decode.c:2539: TCP in_cksum_tcp is 0x5900
3 decode.c:2539: TCP in_cksum_tcp is 0x5d14
6 decode.c:2539: TCP in_cksum_tcp is 0x6100
38 decode.c:2539: TCP in_cksum_tcp is 0x6314
107 decode.c:2539: TCP in_cksum_tcp is 0x6514
8 decode.c:2539: TCP in_cksum_tcp is 0x65ff
1 decode.c:2539: TCP in_cksum_tcp is 0x7378
10 decode.c:2539: TCP in_cksum_tcp is 0x800
23 decode.c:2539: TCP in_cksum_tcp is 0x822d
6 decode.c:2539: TCP in_cksum_tcp is 0x9eff
6 decode.c:2539: TCP in_cksum_tcp is 0xa557
10231 decode.c:2539: TCP in_cksum_tcp is 0xa6ff
17 decode.c:2539: TCP in_cksum_tcp is 0xbc14
477 decode.c:2539: TCP in_cksum_tcp is 0xbe14
10 decode.c:2539: TCP in_cksum_tcp is 0xdb2d
8 decode.c:2539: TCP in_cksum_tcp is 0xf7ff 1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x10
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1000
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1002
2 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1004
2 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1006
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1008
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x101
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1011
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1022
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1024
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x102f
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1031
3 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1035
2 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1036
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1038
2 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1039
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x103a
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x104
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x104f
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1053
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x105f
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1063
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1064
2 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1067
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x1068
1 decode.c:2546: Bad TCP checksum 0x5900 versus 0x106c
------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Config Question, James Jalbert |
|---|---|
| Next by Date: | Re: [Snort-users] Snort vs. gcc 4.1.0, Allen McIntosh |
| Previous by Thread: | [Snort-users] Re: Config Question, Carl Brown |
| Next by Thread: | Re: [Snort-users] Snort vs. gcc 4.1.0, Allen McIntosh |
| Indexes: | [Date] [Thread] [Top] [All Lists] |