[Snort-users] RE: VERY simple 'virtual' honeypot
ryan at ...35...
Fri Mar 8 11:40:08 EST 2002
On Fri, 8 Mar 2002, Ashley Thomas wrote:
> I would think that it is best if the IDS remains in the stealth mode
> without doing anything "active"
I agree. Any response allows for fingerprinting, and potentially being
able to identify the IDS. If I were trying to evade an IDS, the first
thing I would want to know is which one I'm dealing with.
More information about the Snort-users