Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » snort in stealth mode

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

snort in stealth mode


Posted by vvinod1 on March 24, 2005 21:05:56

Hi... can any one help me how to configure snort in stealth mode?..

VVinod.

Posted by novowels on March 26, 2005 12:18:48

To configure Snort in "stealth" mode all you have to do is have it monitoring an interface that does not have an IP or ARP address. Use the -i parameter to specify such an interface.

Posted by christopherccv on May 05, 2005 19:03:05

for me i am using bridging mode for my interface. eth0 & eth1 (0.0.0.0) eth2 (ip address for management purpose)

Posted by geek00L on May 11, 2005 19:47:03

You can either using network tap, or diy your own sniffing cable to get your snort in stealth mode, in order to get snort into steath mode, you are not about configuring snort but more to configuring bridges, network tap deployment or playing with sniffing cable.