BASE - doesn't log PortScan - why?

  • jaro

    jaro - 2007-03-19


    BASE 1.2.7 (karen) doesn't log any PortScan trafic from outside to my IP address, when I scan somebodys IP, I see this in PostScan section.

    TCP, UDP, ICMP monitors works well

    Snort version: snort-mysql (2.3.2-3)

    • Kevin Johnson

      Kevin Johnson - 2007-03-20

      BASE does not log anything, Snort does.  Are you sure that Snort is detecting it?


    • jaro

      jaro - 2007-03-21

      >Are you sure that Snort is detecting it?

      I'm not sure :( how could I check this?
      I can simulate scan to my IP from outside machine.

    • FReeZ

      FReeZ - 2007-05-19

      Your snort is not configured to log port scans, all you need is to "locate snort.conf" and then edit it with your favourite text editor. If locate won't find anything, run updatedb and try again.


