[Snort-users] Professionalism

Gordon Ewasiuk gewasiuk at ...3392...
Tue Nov 13 13:46:03 EST 2001

On Today, Phil Wood wrote:

>Date: Tue, 13 Nov 2001 13:08:47 -0700
>From: Phil Wood <cpw at ...440...>
>To: Joe Smith <shadowm4n at ...131...>
>Cc: snort-users at lists.sourceforge.net
>Subject: Re: [Snort-users] Professionalism
>On Tue, Nov 13, 2001 at 09:54:31AM -0800, Joe Smith wrote:
>> To the administrators of SNORT,
>> An excerpt from "classification.config" from the most
>> recent snort rules download.
>One thing that has not been over stated since the inception of
>the "classification.config" file is the following:
>  As a snort administrator/installer you should edit classification.config
>  to suit the policies of your organization.  At the same time, you should
>  review the rules which you are including in your snort.conf file for
>  appropriateness, and to verify their classification in relation to the
>  changes you made to the classification.config file.  You should not use
>  either the classification.config or rules out of the box.  To do so,
>  is a dereliction of duty.

Damn.  People get a commerical-grade IDS FOR FREE and are bitching about a
simple pr0n rule?  Whoa.  WTF?  Hellooooo.  If you are that "offended" by
SNORT, don't use it.  Go out and pay tens of thousands of dollars for
some crap from McAfee, Cisco, or whoever.

If not, and you enjoy the many, many features and benefits offered by
SNORT, *FOR FREE*, then edit the rule and go about your business.


Gordon Ewasiuk, Certifed Sun Fanatic,  Winstar VHC
The REAL office number is here----->  703.893.4901

Read the story about the #1 Unix Platform

More information about the Snort-users mailing list