[Snort-users] Re: New Snort 2.2 Rules (Walt Rich)

Nigel Houghton nigel at ...1935...
Wed Sep 14 14:01:33 EDT 2005

On  0, snort-users-request at lists.sourceforge.net allegedly wrote:
> Today's Topics:
>    4. New Snort 2.2 Rules (Walt Rich)
> --__--__--
> Message: 4
> Date: Wed, 14 Sep 2005 15:26:31 -0500
> From: "Walt Rich" <walt.rich at ...12648...>
> To: <snort-users at lists.sourceforge.net>
> Subject: [Snort-users] New Snort 2.2 Rules
> I updated the Snort rules to the latest available on Souceforge's site.
> They wre auite out of date, and almost a year old.  Snort is up and
> running, but has become very queit!  It used to detect alot of false
> positives, which were a pain, but at least I knew it was working.  Now
> it is very, very quiet, and hasn't detected anything in over 2 hours.
> Is it possible that the rule writers have become so good that the
> detection of false positives has been almost eliminated?  Has anyone
> else experienced anything similar?  Any input is greatly appreciated.
> =20
> Thanks!=20
> =20
> 	=20
> ________________________________
> | Walt Rich | Sr. Network Engineer | Parago, Inc. | 972.538.7253 |=20
> walt.rich at ...12648... |

You need to get your rules from
http://www.snort.org/pub-bin/downloads.cgi and get the ruleset that
applies to your version of snort. You can register free of charge and
get the VRT rules.

Don't forget to restart snort when you are done updating the rule set. I
might also suggest using oinkmaster to download and keep things up to
date too.

     Nigel Houghton      Research Engineer       Sourcefire Inc.
                   Vulnerability Research Team

 I require a window seat and an inflight Happy Meal, and no pickles! 
 God help you if I find pickles!

More information about the Snort-users mailing list