Snort mailing list archives

Re: Reputation Preprocessor


From: Joel Esler <jesler () sourcefire com>
Date: Mon, 1 Oct 2012 11:04:19 -0400

On Oct 1, 2012, at 10:52 AM, Yonas Abebe <jonasabebe () gmail com> wrote:

OK. Then i have a related question. Is there a way (if any) that i can pass a black list file to snort from Mysql 
database at run time?

No.  The alerts that are generated will have the IP in them when the alert is logged.

I will be putting a blog post together on where you can download a blacklist that we produce here at Sourcefire for use 
for free in the Snort platform.

Putting some details together for publication, but should be either today or tomorrow.  Keep an eye on blog.snort.org.

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire

------------------------------------------------------------------------------
Got visibility?
Most devs has no idea what their production app looks like.
Find out how fast your code is with AppDynamics Lite.
http://ad.doubleclick.net/clk;262219671;13503038;y?
http://info.appdynamics.com/FreeJavaPerformanceDownload.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: