Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk |
|---|---|
| Date: | Tue, 2 Nov 2004 20:21:50 -0500 |
-Marty
On Nov 2, 2004, at 10:40 AM, kquest@toplayer.com wrote:
I'm aware that SourceFire (or whatever it's called) is backing up Snort; however, that's not how Snort started (snort was already there when SourceFile was created, which is similar to what happened with zebra). I'm sorry if my history of snort is not correct, but I thought that's how it was. It's totally opposite to what we have there, where we have.
There's also a difference between what's going on with Snort and this tool. SourceFire makes an IDS tool based on Snort where TippingPoint makes an IPS device and this tool is suppose to test IPSes.
I do have have pcaps to contribute, but I'm definitely not going to give them on a silver platter to TippingPoint. We need a next generation IDS/IPS/whatever testing tool that goes beyond simple pcap replay. We need something that can take a pcap... then fully parse it (not just data link,network, and transport layers) and then have application intelligence to do something actually useful with it (e.g., perform application fragmentation for RPC, etc). The list goes on...
------------------------------------------------------------
- Kyle, Don't forget the 'snort' folks have just as much of a vendor presence as TippingPoint or any other IDS vendor. TippingPoint _may_ be trying to encourage use of their tool for IDS evolution as a whole much like snort has yet still has hopes they will get some benefit from their free tool.
Now do you have any pcaps to contribute to snort or the rest of us packetninjas?
-Dan
----------------------------------------------------------------------- ---
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
----------------------------------------------------------------------- ---
-- Martin Roesch - Founder/CTO, Sourcefire Inc. - +1-410-290-1616 Sourcefire - Discover. Determine. Defend. roesch@sourcefire.com - http://www.sourcefire.com Snort: Open Source Network IDS - http://www.snort.org
-------------------------------------------------------------------------- Test Your IDS
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk, Ron Gula |
|---|---|
| Next by Date: | Re: TippingPoint Releases Open Source Code for First Intrusion Pr evention Test Tool, Tomahawk, ADT |
| Previous by Thread: | RE: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk, kquest |
| Next by Thread: | Re: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk, Greg Shipley |
| Indexes: | [Date] [Thread] [Top] [All Lists] |