|
|
|
|
Snort Forums Archive
Archive Home » Third Party Tools » Arpspoofing préprocessor and acid
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Arpspoofing préprocessor and acid
Posted by nassih50 on August 10, 2005 11:39:51
Hi,
I activate a ARPSpoof preprocessor, it works fine and when I simulate the attack, the alert is displayed in /var/log/snort/alert file.
I have ACID with mysql configured and I want to log this alert in the database, like this I can see it by ACID.
The system log all alerts in the database. I already configure the output to be, to mysql.
thanks in advance |
|
Posted by nassih50 on August 10, 2005 13:47:31
Snort 2.0.1 released |
|
Posted by Joel_Esler on August 28, 2005 06:38:45
I don't think arpspoof is outputted to the database. SOURCEfire does not maintain arpspoof. Aside from
that, you should seriously conside upgrading to the newest version Snort for all of it's latest functionality.
Joel Esler
SOURCEfire |
|
|
|
|
|