Snort mailing list archives

NEWBIE: rule writing walkthru?


From: "Wayne Fielder" <wayne () kentuckyregiments org>
Date: Tue, 13 Jul 2004 09:54:45 -0400

Greetings all,

    I'm brand new to Snort.  Know what it is capable of and want to play
with it but I'm having trouble getting out of the blocks.  I'm reading
through the docs and it seems pretty straight forward but I would like
to find a walkthru/tutorial or something like that for rule writing.

    I'm wanting to use Snort as both an IDS AND a web usage monitor. 
I'm working with a state agency and money is...well...there is no money
to spend on a Netappliance machine or something of that ilk.  I was
thinking that if Snort can detect intrusions it must also be able to do
the web usage thing given the correct rule.

Wayne Fielder
MCP, GSEC, GCIH pending


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: