[Snort-sigs] Sourcefire VRT Certified Snort Rules Update2011-12-07
michael.scheidell at ...1331...
Thu Dec 8 08:28:40 EST 2011
Sure, but if I add the snort.conf file that is rules, overwritting my edited snort.conf file...
It would be worst.
Blog says they would use that var in a specific rule set.
They broke things.
From: Weir, Jason [mailto:jason.weir at ...3410...]
Sent: Thursday, December 08, 2011 8:27 AM
To: Michael Scheidell; snort-sigs at lists.sourceforge.net
Subject: RE: [Snort-sigs] Sourcefire VRT Certified Snort Rules Update2011-12-07
I was thinking that as well - but I'm sure it was in the snort.conf file bundled with the rules...
From: Michael Scheidell [mailto:michael.scheidell at ...1331...]<mailto:[mailto:michael.scheidell at ...1331...]>
Sent: Thursday, December 08, 2011 5:11 AM
To: snort-sigs at lists.sourceforge.net<mailto:snort-sigs at ...3414...t>
Subject: Re: [Snort-sigs] Sourcefire VRT Certified Snort Rules Update2011-12-07
On 12/7/11 4:13 PM, Research wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Sourcefire VRT Certified Snort Rules Update
This release adds and modifies rules in several categories.
you forgot to mention that you broke every snort installation that did not add FILE_DATA_PORTS to their *.conf files.
Michael Scheidell, CTO
Please visit www.nhrs.org<http://www.nhrs.org> to subscribe to NHRS email announcements and updates.
This email has been scanned and certified safe by SpammerTrap(r).
For Information please see http://www.spammertrap.com/
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs