Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » Snort Portscan

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Snort Portscan


Posted by jcb on June 09, 2005 14:17:18

I'm trying to get the old portscan preprocessor to work. I have found that if stream4 detect_scans or flow_portscan is on, the old portscan won't work. Those new ones don't meet my needs because I prefer to get port information of the scans because this makes it particularly easy to pick out machines that are infected with standard windows Virii which is my goal. Right now, I'm getting about nothing out of it. Nmaping generates alerts but no portscan data. About all I'm seeing is traffic out of MSN on port 80 (I guess MSN messenger... don't know).

Any hints?

Posted by roesch on June 29, 2005 18:22:01

Have you tried sfportscan?

-Marty