[Snort-users] RE: VERY simple 'virtual' honeypot

Ryan Russell ryan at ...35...
Fri Mar 8 11:40:08 EST 2002


On Fri, 8 Mar 2002, Ashley Thomas wrote:
> I would think that it is best if the IDS remains in the stealth mode
> without doing anything "active"

I agree.  Any response allows for fingerprinting, and potentially being
able to identify the IDS.  If I were trying to evade an IDS, the first
thing I would want to know is which one I'm dealing with.

					Ryan





More information about the Snort-users mailing list