Snort mailing list archives

general custom rules questions


From: "Basil Saragoza" <snortlst () hotmail com>
Date: Thu, 28 Feb 2002 16:31:58 -0500

1. If I want to create my own rules then should I place it in the
local.rules file or create my own file? (And then use snort -o)
2. As to the flexresp rules...I understand it is quite dangerous and it can
cause more harm than good....is there any tutorial or user archive for
custom written rules?
(UserManual.pdf explains to great extent what the settings are..but it has
no recommendations regarding flexresp rules, only the warning to be careful
not to create loopback traffic)
3. Let's say I created a flexresp rule for some annoying hostile connection,
O.K., now it's dropped. Then hacker figures out what is going on and spoofs
his address to novell.com address, then I can't block it cause I don't want
to block novell.com. It leaves me pretty helpless...is there anything I can
do with snort regarding this or should I rely on anti-spoofing capabilities
of my firewall?
thx.

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: