Snort mailing list archives

Re: NEWBIE: rule writing walkthru?


From: shashank.joshi () tcs com
Date: Wed, 14 Jul 2004 21:08:13 +0530

Snort manual...nothing else required for rules info

Good luck!

Shashank

"It's difficult to improve perfection !"



"Wayne Fielder" <wayne () kentuckyregiments org> 
Sent by: snort-users-admin () lists sourceforge net
07/13/2004 07:24 PM

Please respond to
wayne () kentuckyregiments org


To
snort-users () lists sourceforge net
cc

Subject
[Snort-users] NEWBIE: rule writing walkthru?






Greetings all,

    I'm brand new to Snort.  Know what it is capable of and want to play
with it but I'm having trouble getting out of the blocks.  I'm reading
through the docs and it seems pretty straight forward but I would like
to find a walkthru/tutorial or something like that for rule writing.

    I'm wanting to use Snort as both an IDS AND a web usage monitor. 
I'm working with a state agency and money is...well...there is no money
to spend on a Netappliance machine or something of that ilk.  I was
thinking that if Snort can detect intrusions it must also be able to do
the web usage thing given the correct rule.

Wayne Fielder
MCP, GSEC, GCIH pending


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - 
digital self defense, top technical experts, no vendor pitches, 
unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

ForwardSourceID:NT0000534A 

Attachment: InterScan_Disclaimer.txt
Description:


Current thread: