[Snort-sigs] Snort.conf updates have been posted

Joel Esler jesler at ...435...
Tue Oct 9 15:46:06 EDT 2012


http://blog.snort.org/2012/10/sourcefire-vrt-certified-snort-rules_9.html


The following changes were made to the snort.conf:

portvar HTTP_PORTS [80,81,311,591,593,901,1220,1414,1741,1830,2301,2381,2809,3128,3702,4343,4848,5250,7001,7145,7510,7777,7779,8000,8008,8014,8028,8080,8088,8090,8118,8123,8180,8181,8243,8280,8800,8888,8899,9000,9080,9090,9091,9443,9999,11371,55555] 

now reads:

portvar HTTP_PORTS [80,81,311,591,593,901,1220,1414,1741,1830,2301,2381,2809,3128,3702,4343,4848,5250,7001,7145,7510,7777,7779,8000,8008,8014,8028,8080,8088,8090,8118,8123,8180,8181,8243,8280,8800,8888,8899,9000,9060,9080,9090,9091,9443,9999,11371,55555] 

(Addition of 9060)

The port was also added to stream5 and http_inspect's configuration lines.

I have updated the example snort.conf's, they can be found here: 
http://www.snort.org/vrt/snort-conf-configurations/

Thanks!

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20121009/d63fd118/attachment.html>


More information about the Snort-sigs mailing list