[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: snort-stats without mailing...



On Thu, Feb 13, 2003 at 12:15:55AM +0000, Ricardo Sousa wrote:

> How can i send/view snort stats without mailing them ?!?

I may be missing how snort sends its logs, but:

* If you're reading the mail on the same system that snort's installed
  on, you can use the "local delivery only" option in eximconfig.

* If you're reading the mail on a different system, I'd think you
  could configure exim (or some other MTA) to not listen on any port
  at all (make sure it's not in inetd, and remove all startup links in
  /etc/rc?.d, since snort probably just uses mail, mailx, or pipes to
  /usr/sbin/sendmail.

Neither option should require an open smtp port, and you'd only be
vulnerable to remote holes in snort or ssh, plus local holes in
whatever else is on the system.

-- 
Mike Renfro  / R&D Engineer, Center for Manufacturing Research,
931 372-3601 / Tennessee Technological University -- renfro@tntech.edu



Reply to: