[Snort-sigs] Bleedingsnort.com Daily Update

Brian Caswell bmc at ...95...
Mon Mar 13 20:52:04 EST 2006


On Mar 5, 2006, at 8:00 PM, bleeding at ...2727... wrote:
>  2402000 - BLEEDING-EDGE DROP Dshield Block Listed Source (bleeding- 
> dshield.rules)
>  2403000 - BLEEDING-EDGE DROP Dshield Block Listed Source -  
> BLOCKING (bleeding-dshield-BLOCK.rules)

So, I don't see much discussion about these rules.  Heck, I don't  
think I've seen any.  What is the point in these rules?

Snort can do many things, in fact, if I care to update a plugin I  
wrote many many many years ago, it can even make coffee... but why  
make Snort a firewall?  Wouldn't it be much faster to have the  
firewall do this work, not Snort?

Brian




More information about the Snort-sigs mailing list