Gentoo Archives: gentoo-security

From: Ryan <ryan@×××××.net>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Updating Snort Rules
Date: Mon, 10 May 2004 16:33:28
Message-Id: 3100.68.211.115.247.1084206778.squirrel@hairball.homeip.net
1 Well, i've given oinkmaster a try and like what I see so far. It's really
2 nice that it displays what it is changing. I'm not ready to trust it to a
3 cron job yet (i'll give it some time), but it is exactly what I wanted.
4 Thanks to all who offered suggestions!
5
6 Ryan
7
8 > I too use oinkmaster on a weekly basis to download the current ruleset and
9 > roll in the changes.
10 > As long as you sort out your perms on the /etc/snort directory it's fine.
11 > I just run it from the snort users crontab.
12 >
13 > Regards,
14 > Cammy.
15 >
16 > --
17 > Cameron Logie - Rushbrook IT
18 > Internet | Systems | Security
19 > Linux solutions for forward thinkers
20 >
21 > [W] http://www.rushbrookit.com/
22 > [E] cameron.logie@×××××××××××.com
23 > [T] 0870 765 0620
24 >
25 > GPG Key fingerprint = F83F 9D7F 80FF 79A6 B36D 7C97 7491 5C03 7F2B 65D7
26 > Public Key at http://www.rushbrookit.com/gpgkeys/cameron.logie.gpg.asc
27 >
28 > Ryan said:
29 >> I just recently installed snort on a machine to watch my network. I see
30 >> that there are several scripts out there that support automatic updating
31 >> of the snort ruleset to keep it current. Could anyone recommend a
32 >> program
33 >> for doing that or comment on their experience with them? I'd just like
34 >> to
35 >> have some means of automatically downloading new rules and installing
36 >> them. Also, is there an "emerge snortrules" or some similar ebuild that
37 >> I've missed?
38 >>
39 >> Thanks,
40 >> Ryan
41 >>
42 >> --
43 >> gentoo-security@g.o mailing list
44 >>
45 >>
46 >>
47 >
48 >
49 > --
50 > gentoo-security@g.o mailing list
51 >
52 >
53 >
54
55
56 --
57 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Updating Snort Rules Shane Hickey <shane@×××××××××××××××.com>