[Snort-users] porn.rules

David J. Bianco david at ...13799...
Fri Nov 9 15:02:28 EST 2007


Joel Esler wrote:
> 1)  Don't use ACID.  Use BASE if you wish to maintain that  
> functionality.  base.secureideas.net
> 2)  Don't have Snort writing directly to DB.  Please look into Barnyard.
> 

3) SELECT UNHEX(data_payload) FROM data WHERE sid=XX AND CID=YY;

No need for perl in most cases.

	David




More information about the Snort-users mailing list