Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] how rules work |
|---|---|
| Date: | Tue, 11 Dec 2007 09:58:33 -0800 (PST) |
hi
I am very very new to Snort just downloaded and compiled it. What I need to
know is how rules work. I downloaded the rules from Sourceforce and installed.
I have also setup Base and Mysql to log the traffic. I have a SPAN port
sending information to my SNort box from a paticular VLAN I need to monitor.
Basically can I disable all rules and add them one by one ? and what file
determines what rules to use ?
Will SNORT act as an IPS and kill my network or just it just monitor traffic ?
Also on a seperate note do I need the network interface to operate in pernicios
mode and does this need a specific switch when starting snort.
Thanks for the help
Robert
___________________________________________________________
Support the World Aids Awareness campaign this month with Yahoo! For Good
http://uk.promotions.yahoo.com/forgood/------------------------------------------------------------------------- SF.Net email is sponsored by: Check out the new SourceForge.net Marketplace. It's the best place to buy or sell services for just about anything Open Source. http://sourceforge.net/services/buy/index.php
_______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Newly Released: Aanval Basic, Jeff Dell |
|---|---|
| Next by Date: | Re: [Snort-users] Newly Released: Aanval Basic, Mike Guiterman |
| Previous by Thread: | [Snort-users] Newly Released: Aanval Basic, Aanval dot Com |
| Next by Thread: | Re: [Snort-users] how rules work, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |