Snort mailing list archives
Re: Snort rules updated?
From: Erek Adams <erek () snort org>
Date: Wed, 13 Aug 2003 16:40:07 -0400 (EDT)
On Wed, 13 Aug 2003 CMartin () infosol com wrote:
Just wanted to get the word when the official rule sets get updated with the rules to detect DCOM exploit as well as the worm associated with the exploit (mblaster.exe). I like the idea of adding the rule myself; however, I wouldn't mind bringing my systems up to date by downloading the rule sets with the new rules implemented. I'm hoping the rule sets that are on the site now are updated :)
Join the snort-sigs mailing list. It's been posted numerous times over the last few days. And as for adding rules yourself: Create a "my.rules" and place your rules in there. Then whenever you auto update rules, that won't get overwritten. Be sure and add it to the include lines at the bottom of snort.conf. Cheers! ----- Erek Adams "When things get weird, the weird turn pro." H.S. Thompson ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort rules updated? CMartin (Aug 13)
- RE: Snort rules updated? Jim Grossl (Aug 13)
- Re: Snort rules updated? Erek Adams (Aug 13)
- <Possible follow-ups>
- RE: Snort rules updated? CMartin (Aug 13)
- RE: Snort rules updated? Christopher Lyon (Aug 14)
- RE: Snort rules updated? John York (Aug 14)
- RE: Snort rules updated? Christopher Lyon (Aug 14)