[Snort-users] Firing off Abuse email based on Snort Traffic

scheidell at ...5171... scheidell at ...5171...
Fri May 30 16:50:02 EDT 2003


"Matt Howell" <mhowell at ...9084...> wrote in message news:<1054241161.1810.26.camel at ...9085...>...
> On Thu, 2003-05-29 at 12:07, Matt Kettler wrote:
> > If you were to send me such an 
> that they can address the issue while the host is still active (in
> theory).

Dshield/Aris/mynetwatchman.

_IF_ a source ip does a LOT of nasty stuff, then dshield or mynetwatchman will escalate it, but its go to do a LOT of nasty stuff.

(and portscans, while they might wake you and your pager up at 2am are not much of a reason to tell an isp who is still trying to stop their lusers from launching nimda.. lets get some perspective here)





More information about the Snort-users mailing list