Snort and Wireshark

Discussion in 'Networks' started by Fluid, Jul 25, 2007.

  1. Fluid

    Fluid Byte Poster

    180
    0
    14
    I was wandering are these two softwares the same? has one got any advantages over the other one? Which one do you use and why? I installed wireshark last night and i didnt have a clue on how to use it. Will be reading the tutorials on here when i get home. Also i noticed something else as well.. first i went to download etheral which was 12MB then i realised that its now called wireshark, then i went to download wireshark.. which was under 1MB... why the big difference?
     
  2. simongrahamuk
    Honorary Member

    simongrahamuk Hmmmmmmm?

    6,205
    136
    199
    AFAIK Snort is only for Linux boxes, although I think there was a Snort for Windows under development.
     
  3. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Snort and Wireshark - although they can perform similar functions - are completely different. Whilst Wireshark is an excellent packet sniffer and analyser - that's ALL it is. It allows you to capture and interpret network traffic. Snort is a fully-functional open-source IDS - providing features that you would ususally have to pay thousands - if not TENS of thousands of pounds for in a commercial product. Comparing the two is like comparing a bicycle to a Ferrari.

    Not sure why your download was only 1Mb - the full Wireshark download is around 12Mb (Wireshark is, as you probably know, the 'evolutuion' of Ethereal - which was comparable in size). I suggest that you probably either got a corrupt, half-finished download, or have downloaded something bogus masquerading as Wireshark. The full, bona fide download can be found here
     
    Certifications: A few
    WIP: None - f*** 'em
  4. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Si - Snort is platform independent. I have three Snort IDS boxes running at work on Windows - using the excellent WinSnort All-In-One package. This is a full install of Snort, together with full support for a graphical front end (BASE) running PHP via either Apache or IIS, and logging to a back end DB - supporting MySQL or SQL Server.

    Incidentally, in most cases a solution like this has the snazzy 'LAMP' acronym (Linux, Apache, MySQl, PHP). I guess in this case you could call it 'WIMP' or 'WAMP' :biggrin
     
    Certifications: A few
    WIP: None - f*** 'em
  5. Fluid

    Fluid Byte Poster

    180
    0
    14
    Windows 2000/XP/2003/Vista Installer (.exe)

    * Wiretapped (http, au)

    i downloaded that one from www.wireshark.org

    is snort hard to use? Are there tutorials out there for it? I will be runnign it on windows 2003
     

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.