Snort mailing list archives

Re: Furtner Action


From: Erek Adams <erek () theadamsfamily net>
Date: Wed, 6 Mar 2002 11:22:41 -0800 (PST)

On Wed, 6 Mar 2002, User BALGAA System Engineer wrote:

Now my installed snort-stable working well.
It seems snort is very smart and wonderful software.

I would like to know how can I to prevent/stop/filter attacks detected by
Snort.

Any suggestion?

Yes.  Grab the SnortUsersGuide.pdf from the website and read it.  It details
out how you can use the FlexResp features of snort to do this.

http://www.snort.org/docs/writing_rules/chap2.html#tth_sEc2.3.24

You'll need to compile snort with that feature set turned on.  It will also
require libnet to be installed.

Warning:  This feature can be a double edged sword.  It can harm as much as it
can help.  Please read the warning notes in the docs about why this can be
bad.

Also there are any sites contains useful Snort rules/plugins etc.,?

Almost all known plugins are at http://www.snort.org/ .

Good luck!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: