Snort mailing list archives

Re: where I configure my rules ?


From: John Sage <jsage () finchhaven com>
Date: Fri, 17 Oct 2003 00:02:04 -0700

On Thu, Oct 16, 2003 at 07:18:45PM -0400, Erek Adams wrote:
On Thu, 16 Oct 2003, [ISO-8859-8] ???? wrote:

I have an ordinary network with only mail relay on the dmz. do I need to
configure special rules or the default rules are enough ?

If I need to configure them how I tell snort to check them ?

      vi snort.conf

/* snip */

vi!

Now, *that* is a nasty trick :-)

(given the presumed level of experience of the original poster!)



- John
-- 
"Most people don't type their own logfiles;  but, what do I care?"
-
John Sage: InfoSec Groupie
-
ABCD, EFGH, IJKL, EmEnOh, Pplus+, Mminus-
-
ATTENTION: this entire message is privileged communication, intended
for the sole use of its recipients only. If you read it even though
you know you aren't supposed to, you're a poopy-head.


-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
SourceForge.net hosts over 70,000 Open Source Projects.
See the people who have HELPED US provide better services:
Click here: http://sourceforge.net/supporters.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: