[Snort-users] Public Blacklist usage?

Michael Steele michaels at ...9077...
Mon Feb 25 16:55:58 EST 2013


In pulled pork there is an option to pull a public blacklist:

 

# This format MUST be followed to let pulledpork know that this is a
blacklist

rule_url=http://labs.snort.org/feeds/ip-filter.blf|IPBLACKLIST|open

 

In the snort.conf there is:

 

#    blacklist $BLACK_LIST_PATH/black_list.rules

 

I'm pretty sure PP pulls a public blacklist? If this is so, how do I get
this working, not using PP?

 

Best regards,

Michael...

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130225/30e57d1c/attachment.html>


More information about the Snort-users mailing list