[Snort-users] Humour- Things not to do with your IDS

Adrian Asher adrian at ...675...
Tue Nov 14 02:59:54 EST 2000


could be worse,
you could of had a rule like:

log tcp any any <> $HOME_NET any  (session: all;)

Adrian
----- Original Message -----
From: "andy lowton" <andy at ...586...>
To: <snort-users at lists.sourceforge.net>
Sent: Monday, November 13, 2000 3:21 PM
Subject: [Snort-users] Humour- Things not to do with your IDS


> Nevr temporarily let someone through your firewall to pull a huge file by
> putting in a temporary snort rule to detect their IP, ..............and
> then forgetting to take out the rule before they pull the file.
>
> All together now.......DOH!
>
> l8z
>
> andy
>
>
>
> ---------------------------------------
> E-Mail: andy at ...586...
> PGP/GnuPG Key available on request
> Cultivating a healthy uptime addiction
> ---------------------------------------
>
>
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users




More information about the Snort-users mailing list