Snort mailing list archives

Viirus rules


From: Michael.Mulholland () dfpni gov uk
Date: Mon, 2 Feb 2004 09:01:54 +0000


Folks,

I'm using the IDS Policy Manager to download new rules and push them out to
a number of sensors but the virus set has a note claiming these rules are
not actively updated.

I'm relatively new to Snort so i'm not sure how i should keep my signatures
up-to-date with the large number of virus and other such attacks out there

Do i need to write my own signatures - if so where do i find the details on
what content to scan for?

many thanks to anyone who takes the time to read this and more so to those
who reply

michael mulholland
*******************************************************************************************

Any views expressed by the sender of this message are not necessarily those
of the Department of Finance & Personnel and the Office of the First
Minister and the Deputy First Minister.  This email and any files
transmitted with it are intended solely for the use of the individual or
entity to whom they are addressed.  If you have received this email in
error please notify the sender immediately by using the reply facility in
your email software.  All emails are swept for the presence of viruses.
********************************************************************************************



-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: