Snort mailing list archives

Re: so_rule problem


From: Nigel Houghton <nhoughton () sourcefire com>
Date: Fri, 1 Oct 2010 13:14:31 -0400

On Fri, 01 Oct 2010 12:37:14 -0400, waldo kitty wrote:
On 10/1/2010 10:47, Jimmy Tharel wrote:
I'm trying to get my Snort installation to detect the latest ms10-070
vulnerability. According to
http://www.snort.org/vrt/advisories/2010/09/23/vrt-rules-2010-09-23.html it
should have been included in the rules released on the 23rd.

are you a "registered" user or a "paying subscriber" user? we lowly 
"registered" 
users have to wait 30 days before we get those rules... for easy 
counting, if it 
was released on Sep 23rd, we won't get access to it until Oct 23rd...

i had similar discussion to this some time back in another venue and 
at that 
time the question was does VRT update the "registered" rules snapshot 
every day 
so that there's a "rolling release" or do they simply wait and do one 
release 
every 30 days... AIR, no one ever answered that question or provided 
a pointer 
to where it might be answered...

Didn't see that question, but to answer it. The roll over is automatic.

--
Nigel Houghton
Head Mentalist
SF VRT Department of Intelligence Excellence
http://vrt-sourcefire.blogspot.com && http://labs.snort.org/

------------------------------------------------------------------------------
Start uncovering the many advantages of virtual appliances
and start using them to simplify application deployment and
accelerate your shift to cloud computing.
http://p.sf.net/sfu/novell-sfdev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: