Wednesday, January 30, 2008

Testing your IDS

Is that SPAN still up? Am I seeing the traffic that I need to? IDSwakeup from Herve Schauer Consultants, is a small script the is worth a try. You will have to have hping2 installed as a prereq.

Usage: ./IDSwakeup src_addr dst_addr [nb] [ttl]

IDSwakeup should light the average sensor up like an Xmas Tree.

