Thu Nov 23 16:36:19 EST 2017
means by which to make blackice log certain attacks...
"I can't recommend you use this feature, but it may be interesting
for entertainment purposes. Add the following lines to the
trons = enabled
trons.rule = alert tcp any any -> any any (msg:"URG Scan";flags:U;)
trons.filename = trons-needs-filename-even-if-dont-exist
I can't stress enough that this feature is unsupported and that
you can't get any help from us about this feature at this time.
However, you might find documentation somewhere on the net :-).
As a user, I added those lines and transmitted the packet
described in the NtWaK0 message, and BlackICE triggered on it."
Internet Security Systems
PS: I'll be putting up a small TRONS document up on my personal
website tomorrow. The link will be:
More information about the Snort-users