Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort & Web Attack

    Scheduled Pinned Locked Moved pfSense Packages
    6 Posts 3 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      barisnet
      last edited by

      Hi everybody, i am using snort application on pfsense. i updated all rules and also a web pages on my localhost.
      Download the web stress tester program from the internet after that i run this to this program. This program attack to my localhost but
      Snort is not blocked, not alert messages. i select all rules but snort not gives any attack messages. How can i solve to this problems. Thank a lot.

      1 Reply Last reply Reply Quote 0
      • marcellocM Offline
        marcelloc
        last edited by

        Do you have alerts during web stress test?

        Did you selected block ofenders options on snort configuration?

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • B Offline
          barisnet
          last edited by

          @marcelloc:

          Do you have alerts during web stress test?

          Did you selected block ofenders options on snort configuration?

          No i have not any alert messages. where is the block offers options. i will wait your answer thanks.

          1 Reply Last reply Reply Quote 0
          • B Offline
            barisnet
            last edited by

            i found it but it is checked.

            1 Reply Last reply Reply Quote 0
            • G Offline
              Gloom
              last edited by

              Silly question but you are "attacking" your host via the interface that has snort enabled on it. If you have snort enabled on the WAN but are testing from an internal host then you will get no alerting or blocking.

              Never underestimate the power of human stupidity

              1 Reply Last reply Reply Quote 0
              • B Offline
                barisnet
                last edited by

                @Gloom:

                Silly question but you are "attacking" your host via the interface that has snort enabled on it. If you have snort enabled on the WAN but are testing from an internal host then you will get no alerting or blocking.

                it is not silly question. Snort enabled on the WAN ethernet but it is not give any alertin or blocking messages.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.