Snort mailing list archives

Re: Stopping repeats in Snort/Acid


From: Mike Coles <bluelip () radserv phd-computers com>
Date: Mon, 7 Jan 2002 03:34:24 +0000 (GMT)

My question is this, I'm starting to get listings of people with "Kick-A$$
P0rn" (this appears to be coming through from people getting html spam
mail...among other things ;-)  When I look at ACID to get details on "K-A-P"
I get more alerts from my machine to the ACID box.  How do I keep these from
popping up?  By simply investigating 6 alerts in Acid, I can generate
hundreds of additional alerts.  What's my solution?


        My solution is more of a klidge, but I ssh into the demarc/acid
box, export the display back to my own computer and run netscape. Netscape
will get the demarc/acid page from localhost and not eth? and then
send the display over to your own computer.

Mike Coles


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: