Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] i want to update my snort rules but i don't know how ca

Subject: Re: [Snort-sigs] i want to update my snort rules but i don't know how can i do?
Date: Mon, 24 Oct 2005 07:01:05 -0500
Quoting zahra taghikhaki <physicminister@yahoo.com>:

hi
i installed snort with default rules .i want to update
and use new snort rules .
how can i do it?
where can i find rules that describe new worms ?


Downloading the rules is easy. You should use two main sources: www.bleedingsnort.org and www.snort.org.

For the bleeding snort rules, use this URL:

http://www.bleedingsnort.com/bleeding-all.rules

OK.  Now the easy part is over.

You should use a rule management system of some kind. Lots of people have written their own, but oinkmaster seems to be the most frequently referenced. Get oinkmaster here: http://oinkmaster.sourceforge.net/ Without a rule management system of some kind, you will not like snort.

To download signatures from snort.org, you should visit their site. They have a fantastically confusing way of describing their offerings. I will not repeat it here. If you register with snort.org and get an "oinkcode" then you oinkmaster installation will seamlessly pick up the snort.org sigs.

hope this gets you started.

jp

-------------------------------------------------
Email solutions, MS Exchange alternatives and extrication,
security services, systems integration.
Contact:    services@doctorunix.com




------------------------------------------------------- This SF.Net email is sponsored by the JBoss Inc. Get Certified Today * Register for a JBoss Training Course Free Certification Exam for All Training Attendees Through End of 2005 Visit http://www.jboss.com/services/certification for more information _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>
  • Re: [Snort-sigs] i want to update my snort rules but i don't know how can i do?, Jack Pepper <=