Snort mailing list archives
Re: Add'l lookup info from within ACID?
From: John Sage <jsage () finchhaven com>
Date: Sat, 04 Aug 2001 08:02:31 -0700
I don't know about ACID (heh.. haven't touched acid in 25 years.. ;-) but a great manual tool that can be integrated into Perl programs is BW Whois by Bill Weinman.
See: http://whois.bw.org/Currently at ver. 2.9, it does a pretty good job of burrowing down to those obscure whois servers scattered all around the planet.
Works from a cli, or you can set up a local cgi-based web page, or, again, call it from Perl.
Apparently it *can* be prodded into working on Window$ platforms... HTH.. - John -- John Sage FinchHaven, Vashon Island, WA, USA http://www.finchhaven.com/ mailto:jsage () finchhaven com "The web is so, like, five minutes ago..." Tom Sevy wrote:
Is there any way to enhance the ACID lookups of IP addresses? I find that I am seeing IP addresses that don't have reverse mappings. So I go to arin.net to lookup who they belong to. It would be great that if the FQDN can't be determined that the IP be looked up in ARIN so at least the owner info could be easily found out. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Add'l lookup info from within ACID? Tom Sevy (Aug 04)
- Re: Add'l lookup info from within ACID? John Sage (Aug 04)