[Snort-devel] IPv6 support in Snort

Martin Roesch roesch at ...402...
Sat Jan 4 21:29:01 EST 2003


I'm working on it (slowly).  I've got a basic IPv6 decoder wired into 
Snort and printout support in log.c, but it's not integrated with the 
detection engine at all yet.  Check out 
http://www.snort.org/~roesch/snort-2.0.0beta-ipv6.tar.gz if you want to 
take a look at it.  I still need to implement defrag support and read 
the full IPv6 RFCs to make sure I haven't missed anything critical.  
The decoder must be rock solid before we go on to implementing 
detection modules....

      -Marty


On Tuesday, December 24, 2002, at 10:47 PM, Marcelo de Souza wrote:

>
> Hello folks,
>
> I'd like to know if is there any active developer or team working 
> around IPv6
> support for Snort.
>
> I'm a IDS enthusiast and developer, and I'd like to hear your opinions 
> about
> adding IPv6 support on Snort (if there is Ipv6 support under 
> development
> already, sorry for my delay and ignorance).
>
> What do u think about overall IPv6 intrusion detection? Is it worth 
> the cost?
>
> I'd be glad to start (or help) some IPv6 support development for 
> Snort. Is
> there anyone that could join me?
>
> Thanks for your attention.
>
> ------------------------------------------------------------
>    - MARCELO DE SOUZA -            <marcelo at ...1753...>
>
>    Computer Science / UNESP - S. J. Rio Preto, SP, Brazil
>
>          -- ACME! Computer Security Research --
>
>             http://www.acme-ids.org/~marcelo
> ------------------------------------------------------------
>
>
> -------------------------------------------------
>        ACME! Computer Security Research
>            http://www.acme-ids.org
>
>
> -------------------------------------------------------
> This sf.net email is sponsored by:ThinkGeek
> Welcome to geek heaven.
> http://thinkgeek.com/sf
> _______________________________________________
> Snort-devel mailing list
> Snort-devel at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-devel
>
>
-- 
Martin Roesch - Founder/CTO Sourcefire Inc. - (410) 290-1616
Sourcefire: Enterprise-class Intrusion detection built on Snort
roesch at ...402... - http://www.sourcefire.com
Snort: Open Source Network IDS - http://www.snort.org





More information about the Snort-devel mailing list