Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 03/24/12 08:42:31 AM mobius-Inspiron-N5110 rsyslogd [origin software="rsyslogd" swVersion="4.6.4" x-pid="798" x-info="http://www.rsyslog.com"] rsyslogd was HUPed, type 'lightweight'.
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] *** Caught Term-Signal
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Run time prior to being shutdown was 2047.325326 seconds
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Packet Wire Totals:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Received: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Analyzed: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Dropped: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Outstanding: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Breakdown by protocol (includes rebuilt packets):
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ETH: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ETHdisc: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] VLAN: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IPV6: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IP6 EXT: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IP6opts: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IP6disc: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IP4: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IP4disc: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP 6: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP 6: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMP6: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMP-IP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCPdisc: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDPdisc: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMPdis: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] FRAG: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] FRAG 6: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ARP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] EAPOL: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ETHLOOP: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] IPX: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] OTHER: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] DISCARD: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] InvChkSum: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] S5 G 1: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] S5 G 2: 0 (0.000%)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Total: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Action Stats:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ALERTS: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] LOGGED: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] PASSED: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Frag3 statistics:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Total Fragments: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Frags Reassembled: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Discards: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Memory Faults: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Timeouts: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Overlaps: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Anomalies: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Alerts: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Drops: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] FragTrackers Added: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] FragTrackers Dumped: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] FragTrackers Auto Freed: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Frag Nodes Inserted: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Frag Nodes Deleted: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Stream5 statistics:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Total sessions: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP sessions: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP sessions: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMP sessions: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Prunes: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Prunes: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ICMP Prunes: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP StreamTrackers Created: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP StreamTrackers Deleted: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Timeouts: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Overlaps: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Segments Queued: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Segments Released: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Rebuilt Packets: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Segments Used: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Discards: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Sessions Created: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Sessions Deleted: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Timeouts: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Discards: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Events: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Internal Events: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] TCP Port Filter
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Dropped: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Inspected: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Tracked: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] UDP Port Filter
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Dropped: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Inspected: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Tracked: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] dcerpc2 Preprocessor Statistics
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Total sessions: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] ===============================================================================
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Could not remove pid file /var/run//snort_eth0.pid: Permission denied
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[1606] Snort exiting
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Running in IDS mode
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] --== Initializing Snort ==--
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Initializing Output Plugins!
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Initializing Preprocessors!
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Initializing Plug-ins!
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Parsing Rules file "/etc/snort/snort.conf"
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] PortVar 'HTTP_PORTS' defined :
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] [ 80 ]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] PortVar 'SHELLCODE_PORTS' defined :
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] [ 0:79 81:65535 ]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] PortVar 'ORACLE_PORTS' defined :
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] [ 1521 ]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] PortVar 'FTP_PORTS' defined :
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] [ 21 ]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Tagged Packet Limit: 256
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic engine /usr/lib/snort_dynamicengine/libsf_engine.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading all dynamic preprocessor libs from /usr/lib/snort_dynamicpreprocessor/...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_ssh_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_ftptelnet_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_smtp_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_dce2_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_dcerpc_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_ssl_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//libsf_dns_preproc.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Loading dynamic preprocessor library /usr/lib/snort_dynamicpreprocessor//lib_sfdynamic_preprocessor_example.so...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] done
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Finished Loading all dynamic preprocessor libs from /usr/lib/snort_dynamicpreprocessor/
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Log directory = /var/log/snort
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Frag3 global config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max frags: 65536
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Fragment memory cap: 4194304 bytes
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Frag3 engine config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Target-based policy: FIRST
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Fragment timeout: 60 seconds
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Fragment min_ttl: 1
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Fragment Problems: 1
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Overlap Limit: 10
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Min fragment Length: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Stream5 global config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Track TCP sessions: ACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max TCP sessions: 8192
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Memcap (for reassembly packet storage): 8388608
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Track UDP sessions: INACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Track ICMP sessions: INACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Log info if session memory consumption exceeds 1048576
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Stream5 TCP Policy config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Reassembly Policy: FIRST
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Timeout: 30 seconds
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Min ttl: 1
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Maximum number of bytes to queue per session: 1048576
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Maximum number of segs to queue per session: 2621
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Reassembly Ports:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 21 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 23 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 25 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 42 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 53 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 80 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 110 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 111 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 135 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 136 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 137 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 139 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 143 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 445 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 513 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 514 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 1433 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 1521 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 2401 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 3306 client (Footprint)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] HttpInspect Config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] GLOBAL CONFIG
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Pipeline Requests: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Inspection Type: STATELESS
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Detect Proxy Usage: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Unicode Map Filename: /etc/snort/unicode.map
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Unicode Map Codepage: 1252
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] DEFAULT SERVER CONFIG:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Server profile: All
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports: 80 8080 8180
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Server Flow Depth: 300
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Client Flow Depth: 300
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Chunk Length: 500000
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Header Field Length: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Number Header Fields: 0
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Inspect Pipeline Requests: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] URI Discovery Strict Mode: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Allow Proxy Usage: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Disable Alerting: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Oversize Dir Length: 500
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Only inspect URI: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Normalize HTTP Headers: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Normalize HTTP Cookies: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ascii: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Double Decoding: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] %U Encoding: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Bare Byte: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Base36: OFF
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] UTF 8: OFF
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Unicode: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Multiple Slash: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Backslash: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Directory Traversal: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Web Root Traversal: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Apache WhiteSpace: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Delimiter: YES alert: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] IIS Unicode Map: GLOBAL IIS UNICODE MAP CONFIG
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Non-RFC Compliant Characters: NONE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Whitespace Characters: 0x09 0x0b 0x0c 0x0d
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] rpc_decode arguments:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports to decode RPC on: 111 32771
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] alert_fragments: INACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] alert_large_fragments: ACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] alert_incomplete: ACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] alert_multiple_requests: ACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Portscan Detection Config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Detect Protocols: TCP UDP ICMP IP
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Detect Scan Type: portscan portsweep decoy_portscan distributed_portscan
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Sensitivity Level: Low
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Memcap (in bytes): 10000000
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Number of Nodes: 36900
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] FTPTelnet Config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] GLOBAL CONFIG
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Inspection Type: stateful
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Check for Encrypted Traffic: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Continue to check encrypted data: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] TELNET CONFIG:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports: 23
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Are You There Threshold: 200
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Normalize: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Detect Anomalies: NO
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] FTP CONFIG:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] FTP Server: default
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports: 21
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Check for Telnet Cmds: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ignore Telnet Cmd Operations: OFF
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Identify open data channels: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] FTP Client: default
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Check for Bounce Attacks: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Check for Telnet Cmds: YES alert: YES
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ignore Telnet Cmd Operations: OFF
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Response Length: 256
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SMTP Config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports: 25 587 691
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Inspection Type: Stateful
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Normalize: EXPN RCPT VRFY
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ignore Data: No
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ignore TLS Data: No
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ignore SMTP Alerts: No
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Command Line Length: Unlimited
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Specific Command Line Length:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] ETRN:500 EXPN:255 HELO:500 HELP:500 MAIL:260
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] RCPT:300 VRFY:255
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Header Line Length: Unlimited
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Response Line Length: Unlimited
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] X-Link2State Alert: Yes
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Drop on X-Link2State Alert: No
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Alert on commands: None
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SSH config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Autodetection: DISABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Challenge-Response Overflow Alert: ENABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SSH1 CRC32 Alert: ENABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Server Version String Overflow Alert: ENABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Protocol Mismatch Alert: ENABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Bad Message Direction Alert: DISABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Bad Payload Size Alert: DISABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Unrecognized Version Alert: DISABLED
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Encrypted Packets: 20
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Max Server Version String Length: 80 (Default)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] MaxClientBytes: 19600 (Default)
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] #01122
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] DCE/RPC 2 Preprocessor Configuration
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Global Configuration
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] DCE/RPC Defragmentation: Enabled
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Memcap: 102400 KB
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Events: none
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Server Default Configuration
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Policy: WinXP
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Detect ports
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SMB: 139 445
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] TCP: 135
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] UDP: 135
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] RPC over HTTP server: 593
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] RPC over HTTP proxy: None
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Autodetect ports
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SMB: None
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] TCP: 1025-65535
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] UDP: 1025-65535
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] RPC over HTTP server: 1025-65535
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] RPC over HTTP proxy: None
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Maximum SMB command chaining: 3 commands
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] DNS config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] DNS Client rdata txt Overflow Alert: ACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Obsolete DNS RR Types Alert: INACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Experimental DNS RR Types Alert: INACTIVE
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 53
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] SSLPP config:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Encrypted packets: not inspected
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Ports:
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 443 465 563 636 989
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 992 993 994 995
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Server side data is trusted
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] +++++++++++++++++++++++++++++++++++++++++++++++++++
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Initializing rule chains...
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] Warning: /etc/snort/rules/dos.rules(42) => threshold (in rule) is deprecated; use detection_filter instead.
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 3381 Snort rules read
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 3381 detection rules
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 0 decoder rules
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 0 preprocessor rules
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 3381 Option Chains linked into 280 Chain Headers
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] 0 Dynamic rules
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478] +++++++++++++++++++++++++++++++++++++++++++++++++++
- 03/24/12 08:42:32 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-------------------[Rule Port Counts]---------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | tcp udp icmp ip
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | src 121 19 0 0
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | dst 2921 130 0 0
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | any 115 53 56 27
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | nc 31 10 15 20
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | s+d 12 6 0 0
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +----------------------------------------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[detection-filter-config]------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | memory-cap : 1048576 bytes
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[detection-filter-rules]-------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | none
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] -------------------------------------------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[rate-filter-config]-----------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | memory-cap : 1048576 bytes
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[rate-filter-rules]------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | none
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] -------------------------------------------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[event-filter-config]----------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | memory-cap : 1048576 bytes
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[event-filter-global]----------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | none
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[event-filter-local]-----------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2523 type=Both tracking=dst count=10 seconds=10
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2275 type=Threshold tracking=dst count=5 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000312 type=Limit tracking=src count=1 seconds=360
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000158 type=Both tracking=src count=100 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000923 type=Threshold tracking=dst count=200 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000160 type=Both tracking=src count=300 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2923 type=Threshold tracking=dst count=10 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000163 type=Both tracking=src count=100 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2924 type=Threshold tracking=dst count=10 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2494 type=Both tracking=dst count=20 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000310 type=Limit tracking=src count=1 seconds=360
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000159 type=Both tracking=src count=100 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000161 type=Both tracking=dst count=100 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=3273 type=Threshold tracking=src count=5 seconds=2
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=3152 type=Threshold tracking=src count=5 seconds=2
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000311 type=Limit tracking=src count=1 seconds=360
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2496 type=Both tracking=dst count=20 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=100000162 type=Both tracking=src count=100 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | gen-id=1 sig-id=2495 type=Both tracking=dst count=20 seconds=60
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] +-----------------------[suppression]------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] | none
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] -------------------------------------------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Rule application order: activation->dynamic->pass->drop->alert->log
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Verifying Preprocessor Configurations!
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Warning: flowbits key 'ms_sql_seen_dns' is checked but not ever set.
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Warning: flowbits key 'realplayer.playlist' is checked but not ever set.
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Warning: flowbits key 'smb.tree.create.llsrpc' is set but not ever checked.
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Warning: flowbits key 'community_uri.size.1050' is set but not ever checked.
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] 37 out of 512 flowbits in use.
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Initializing Network Interface eth0
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Initializing daemon mode
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2478] Daemon parent exiting
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Daemon initialized, signaled parent pid: 2478
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Checking PID path...
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] PID path stat checked out ok, PID path set to /var/run/
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Writing PID "2480" to file "/var/run//snort_eth0.pid"
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Decoding Ethernet on interface eth0
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] [ Port Based Pattern Matching Memory ]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] +-[AC-BNFA Search Info Summary]------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Instances : 241
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Patterns : 22048
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Pattern Chars : 207212
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Num States : 137800
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Num Match States : 18343
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Memory : 3.51Mbytes
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Patterns : 0.70M
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Match Lists : 0.96M
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] | Transitions : 1.79M
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] +-------------------------------------------------
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480]
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] --== Initialization Complete ==--
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Snort initialization completed successfully (pid=2480)
- 03/24/12 08:42:33 AM mobius-Inspiron-N5110 snort[2480] Not Using PCAP_FRAMES
- 03/24/12 08:42:50 AM mobius-Inspiron-N5110 anacron[1082] Job `cron.daily' terminated (exit status: 1) (mailing output)
- 03/24/12 08:42:50 AM mobius-Inspiron-N5110 anacron[1082] Tried to mail output of job `cron.daily', but mailer process (/usr/sbin/sendmail) exited with ststus 255
- 03/24/12 08:42:50 AM mobius-Inspiron-N5110 anacron[1082] Normal exit (1 job run)
- 03/24/12 09:17:01 AM mobius-Inspiron-N5110 CRON[2554] (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
- 03/24/12 09:42:03 AM mobius-Inspiron-N5110 NetworkManager[889] <info> (wlan0): supplicant connection state: completed -> group handshake
- 03/24/12 09:42:03 AM mobius-Inspiron-N5110 wpa_supplicant[977] WPA: Group rekeying completed with a0:21:b7:b0:b4:5e [GTK=TKIP]
- 03/24/12 09:42:03 AM mobius-Inspiron-N5110 NetworkManager[889] <info> (wlan0): supplicant connection state: group handshake -> completed
- 03/24/12 10:17:01 AM mobius-Inspiron-N5110 CRON[2609] (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
- 03/24/12 10:42:04 AM mobius-Inspiron-N5110 NetworkManager[889] <info> (wlan0): supplicant connection state: completed -> group handshake
- 03/24/12 10:42:04 AM mobius-Inspiron-N5110 wpa_supplicant[977] WPA: Group rekeying completed with a0:21:b7:b0:b4:5e [GTK=TKIP]
- 03/24/12 10:42:04 AM mobius-Inspiron-N5110 NetworkManager[889] <info> (wlan0): supplicant connection state: group handshake -> completed
- 03/24/12 10:56:29 AM mobius-Inspiron-N5110 kernel [10112.861196] device wlan0 entered promiscuous mode
- 03/24/12 11:17:01 AM mobius-Inspiron-N5110 CRON[3238] (root) CMD ( cd / && run-parts --report /etc/cron.hourly)
Advertisement
Add Comment
Please, Sign In to add comment