Gentoo Archives: gentoo-security

From: xyon <xyon@×××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Snort alert with Squid ?
Date: Sun, 06 Nov 2005 20:53:37
Message-Id: ME-1EYrJL-0001DR-OX@indigorobot.com
In Reply to: Re: [gentoo-security] Snort alert with Squid ? by "Brian G. Peterson"
1 I concur. Snort is a great program, but the false positives are many.
2 What are the errors that it is tripping? Many people have to
3 custom-tailor their snort rules (by disabling problem rules) to allow
4 legitimate traffic.
5
6 One thing that helps me is I have snort emerged with 'USE="flexresp
7 inline"', and then used oinkmaster to convert all my tcp alert rules to
8 drop. It helps a little in diagnosing false positives.
9
10
11
12 On Sun, 2005-11-06 at 11:21 -0600, Brian G. Peterson wrote:
13 > On Sunday 06 November 2005 10:03 am, aa6qn@×××××××××××.net wrote:
14 > > I could use some help here. I have emerged Snort on my system here (along
15 > > with SnortSnarf) and have been watching the alerts. What is causing my
16 > > concern it that my server is being reported as a source for serveral web
17 > > based attack signatures to a host of unknown destinations. I have spent
18 > > some time cleaning and rebuilding the server with no luck until I turned
19 > > off Squid.
20 >
21 > Could you please paste in copies of the warnings/alerts;log entries you are
22 > seeing?
23 >
24 > Also, have you done a packet capture manually on that port to see what is
25 > going on?
26 >
27 > It is about equally likely that snort is giving you a false positive as it is
28 > that anything is wrong with squid...
29 >
30 > Regards,
31 >
32 > - Brian
33
34 --
35 gentoo-security@g.o mailing list