Snort & Web Attack



  • Hi everybody, i am using snort application on pfsense. i updated all rules and also a web pages on my localhost.
    Download the web stress tester program from the internet after that i run this to this program. This program attack to my localhost but
    Snort is not blocked, not alert messages. i select all rules but snort not gives any attack messages. How can i solve to this problems. Thank a lot.



  • Do you have alerts during web stress test?

    Did you selected block ofenders options on snort configuration?



  • @marcelloc:

    Do you have alerts during web stress test?

    Did you selected block ofenders options on snort configuration?

    No i have not any alert messages. where is the block offers options. i will wait your answer thanks.



  • i found it but it is checked.



  • Silly question but you are "attacking" your host via the interface that has snort enabled on it. If you have snort enabled on the WAN but are testing from an internal host then you will get no alerting or blocking.



  • @Gloom:

    Silly question but you are "attacking" your host via the interface that has snort enabled on it. If you have snort enabled on the WAN but are testing from an internal host then you will get no alerting or blocking.

    it is not silly question. Snort enabled on the WAN ethernet but it is not give any alertin or blocking messages.


Locked