Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] virus rules

Subject: Re: [Snort-sigs] virus rules
Date: Tue, 25 Jan 2005 22:12:18 -0500
I think that was intended to be a call for volunteers to do the maintaining. :) If you're interested there's always room for help.

The most recent sigs are on bleedingsnort.com, but don't consider it complete. if you'd like to contribute we'd welcome the new sigs. But ids signatures really aren't an effective AV tool.

If you really want to get AV via snort look into the clamav snort preprocessor, very effective if you can run snort on a blocking device.

Matt

John Hally wrote:

Actually, I'm using IDS policy Manager, and under the Virus Rules, it says
to send email to snort-sigs if you want to update these rules.  I found this
a little strange, but figured I'd give it a shot.

"NOTE: These rules are NOT being actively maintained.  If you would like to
update these rules, e-mail snort-sigs@lists.sourceforge.net"






------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>