Snort mailing list archives

Re: BPF Filters


From: Nigel Houghton <nhoughton () sourcefire com>
Date: Fri, 21 Aug 2009 11:02:09 -0400

On Fri, Aug 21, 2009 at 10:47 AM, Tommie Giles<tgiles () gmail com> wrote:
Hi, All.

I've started documenting use, care, and feeding of BPF filters in
snort and was curious if anyone else would be interested in reviewing.
I'm about six pages into it, and plan to have something usable in the
next week or so.

I use BPF filters pretty extensively here at work, but haven't really
come across any "definitive" documentation, other than the bit that is
available in the tcpdump man page and the odd google search.

Cheers,

tom



--
Tommie Giles

"If all else fails, immortality can always be assured by spectacular error."

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



I'm sure there are many people on this list who could benefit from
your work. If you can make them available online and send the link to
the list, I'm sure you will get many eyes on it. If you would like us
to host it on snort.org, we can do that for you too.

-- 
Nigel Houghton
Head Mentalist
SF VRT
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: