Solved

Snort rule to alert on a single IP port 80 traffic ??

Posted on 2004-09-02
3
424 Views
Last Modified: 2012-06-27
I need to monitor a specific users traffic on port 80 and I would like to use a Snort alert rule so that the traffic is stored in mysql on my IDS box.

I have tried this simple rule but it does not work.  IP changed to protect the innocent :-)

alert tcp 10.x.x.x 80 -> any any (msg:"10.x.x.x Web Traffic Alert";)

Since my Snort box sits between the firewall and the main router, it is ideal for monitoring the traffic.

Can anyone give me a rule that will accomplish what I need?

Thanks,

Craig
0
Comment
Question by:Craig Sharp
  • 2
3 Comments
 
LVL 4

Accepted Solution

by:
syn_ack_fin earned 500 total points
ID: 11965592
Try this one:
alert tcp 10.x.x.x any -> any 80
or if correct variables are set
alert tcp $HOME_NET any -> $EXTERNAL_NET 80

The source port will not be 80 the destination port will be.

Good luck.
0
 
LVL 3

Author Comment

by:Craig Sharp
ID: 11971551
Since I want to monitor traffic from a single source address, would I write the rule like this?

alert tcp 10.50.x.x any -> any 80 (msg:"10.50.x.x Web Traffic Alert";)
0
 
LVL 4

Expert Comment

by:syn_ack_fin
ID: 11992598
Yes, that should work. The only problem with your original rule was that the ports were switched. Your rule was looking for traffic with a source port of 80, not destination.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Enterprise Password Manager Suites as well as Local Password managers are covered in this article.
As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question