[prev in list] [next in list] [prev in thread] [next in thread] 

List:       snort-devel
Subject:    Re: [Snort-devel] Stateful Snort?
From:       Fyodor <fygrave () tigerteam ! net>
Date:       2001-06-20 11:34:45
[Download RAW message or body]

> Pardon me for being clueless, but its been a _long_ day...
> 
> Does snort keep state?  If I read the code correctly, it doesn't.  But, it's
> late and my brain is coffeless.
> 

Nope it doesn't do stateful inspection. Not in this sense. (see below)

> due to IDS admins not properly excluding their own DNS servers from the
> "DNS source porting attack".  However, that's not what is going on here.
> 
> >
> > The most likely explanation is that Snort "lost state" on your outgoing DNS
> > queries, because I.gtld-servers.net is taking too long to answer.
> 
> I don't think DNS is one of the items Snort keeps state on.
> 

Correct. Snort doesn't keep state of the DNS queries. All it does is
ignoring UDP packets to port 53 of your DNS servers from your internal
network (which is basically the matter of tuning configuration/rules,
not the snort itself).

-F
-- 
http://www.notlsd.net
PGP fingerprint = 56DD 1511 DDDA 56D7 99C7  B288 5CE5 A713 0969 A4D1

_______________________________________________
Snort-devel mailing list
Snort-devel@lists.sourceforge.net
http://lists.sourceforge.net/lists/listinfo/snort-devel

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic