Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Snort rule to alert on a single IP port 80 traffic ??

Posted on 2004-09-02
3
Medium Priority
?
447 Views
Last Modified: 2012-06-27
I need to monitor a specific users traffic on port 80 and I would like to use a Snort alert rule so that the traffic is stored in mysql on my IDS box.

I have tried this simple rule but it does not work.  IP changed to protect the innocent :-)

alert tcp 10.x.x.x 80 -> any any (msg:"10.x.x.x Web Traffic Alert";)

Since my Snort box sits between the firewall and the main router, it is ideal for monitoring the traffic.

Can anyone give me a rule that will accomplish what I need?

Thanks,

Craig
0
Comment
Question by:Craig Sharp
  • 2
3 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 2000 total points
ID: 11965592
Try this one:
alert tcp 10.x.x.x any -> any 80
or if correct variables are set
alert tcp $HOME_NET any -> $EXTERNAL_NET 80

The source port will not be 80 the destination port will be.

Good luck.
0
 
LVL 3

Author Comment

by:Craig Sharp
ID: 11971551
Since I want to monitor traffic from a single source address, would I write the rule like this?

alert tcp 10.50.x.x any -> any 80 (msg:"10.50.x.x Web Traffic Alert";)
0
 
LVL 4

Expert Comment

by:syn_ack_fin
ID: 11992598
Yes, that should work. The only problem with your original rule was that the ports were switched. Your rule was looking for traffic with a source port of 80, not destination.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s a season to be thankful, and we’re thankful for users like you who engage on site, solve technology problems, and network with others in the industry. What tech are we most thankful for? Keep reading.
Spectre and Meltdown, how it affects me and my clients?
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
Suggested Courses

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question