Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

[Snort-users] how rules work

Subject: [Snort-users] how rules work
Date: Tue, 11 Dec 2007 09:58:33 -0800 (PST)
hi

I am very very new to Snort just downloaded and compiled it.  What I need to 
know is how rules work. I downloaded the rules from Sourceforce and installed. 
I have also setup Base and Mysql to log the traffic.  I have a SPAN port 
sending information to my SNort box from a paticular VLAN I need to monitor.

Basically can I disable all rules and add them one by one ? and what file 
determines what rules to use ?  
Will SNORT act as an IPS and kill my network or just it just monitor traffic ?

Also on a seperate note do I need the network interface to operate in pernicios 
mode and does this need a specific switch when starting snort.

Thanks for the help
Robert


      ___________________________________________________________
Support the World Aids Awareness campaign this month with Yahoo! For Good 
http://uk.promotions.yahoo.com/forgood/
-------------------------------------------------------------------------
SF.Net email is sponsored by: 
Check out the new SourceForge.net Marketplace.
It's the best place to buy or sell services for
just about anything Open Source.
http://sourceforge.net/services/buy/index.php
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
<Prev in Thread] Current Thread [Next in Thread>