[Snort-users] Reputation Preprocessor

Yonas Abebe jonasabebe at ...11827...
Mon Oct 1 10:52:40 EDT 2012


Hi Esler,

OK. Then i have a related question. Is there a way (if any) that i can pass
a black list file to snort from Mysql database at run time?

Thanks a lot
jonas

On Tue, Sep 25, 2012 at 5:28 PM, Joel Esler <jesler at ...1935...> wrote:

> On Sep 25, 2012, at 5:04 AM, Yonas Abebe <jonasabebe at ...11827...> wrote:
>
> Does the reputation preprocessor of Snort simply drops packets coming
> from/to IP addresses listed in black list file?
>
>
> Yes.  The whitelist file tells Snort explicitly "Do not block these"
>
> Or do I have to create rules for those IP addresses in the the black list
> file?
>
>
> There should be two rules to uncomment in the preprocessor.rules file in
> order to make it work properly.
>
> --
> Joel Esler
> Senior Research Engineer, VRT
> OpenSource Community Manager
> Sourcefire
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121001/c851a60d/attachment.html>


More information about the Snort-users mailing list