Snort mailing list archives
Re: Snort 2.8 and SID on pass- and alert-rules
From: "David J. Bianco" <david () vorant com>
Date: Mon, 22 Oct 2007 09:00:08 -0400
Vidar Hoel wrote:
If you are right, and I have no reason to believe otherwise, what then the point of pass-rules? I mean, if it's not working they way we have used these pass-rules, what other ways do people use pass-rules?
You're using the pass rules properly, it's only the sid values that are
wrong. As Seth already mentioned elsewhere in the thread, you can use the
pass rules but just change the way you associate them with the original
rules. Personally, I don't use pass rules much, but when I do I put them
just before the rule they go with, and I include comments to make clear
the relationship between the two and why the pass rule is necessary.
David
-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort 2.8 and SID on pass- and alert-rules Vidar Hoel (Oct 18)
- Re: Snort 2.8 and SID on pass- and alert-rules David J. Bianco (Oct 18)
- Re: Snort 2.8 and SID on pass- and alert-rules Vidar Hoel (Oct 18)
- Re: Snort 2.8 and SID on pass- and alert-rules David J. Bianco (Oct 18)
- Re: Snort 2.8 and SID on pass- and alert-rules Vidar Hoel (Oct 19)
- Re: Snort 2.8 and SID on pass- and alert-rules Seth (Oct 19)
- Re: Snort 2.8 and SID on pass- and alert-rules David J. Bianco (Oct 22)
- Re: Snort 2.8 and SID on pass- and alert-rules Vidar Hoel (Oct 18)
- Re: Snort 2.8 and SID on pass- and alert-rules David J. Bianco (Oct 18)
