Snort mailing list archives

VRT Release 2010-02-23 uses "detection_filter"


From: "evilghost () packetmail net" <evilghost () packetmail net>
Date: Wed, 24 Feb 2010 09:26:19 -0600

While I truly enjoy surprises sometimes I'm disappointed when the gift 
isn't something I wanted.  In this case the gift was given to me by VRT 
and came in the form of "detection_filter".  As I eagerly unpacked the 
tar-gzip, giddy like the child on Christmas morning, my happiness turned 
to sadness.  Santa brought me some coal, have I really been that bad?  
It made my 2.8.4.1 Snorts become very unhappy (evidently they don't like 
surprises like I do).  Sure I can sed these out but a little advance 
warning is nice.  Note, advance warning does not constitute "Snort 2.8.5 
is current, you should be running it" or the genetic catch-all warning 
currently in place.  Specific warnings such as "These VRT rules are 
using detection_filter" would be highly appreciated and would allow me 
react accordingly before I dropped a few depth-charges on my Snorts.

http://www.snort.org/vrt/docs/ruleset_changelogs/2_8/changes-2010-02-23.html

-evilghost


------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs


Current thread: