Gentoo Archives: gentoo-security

From: Joey McCoy <ixion@××××××.com>
To: Cameron Logie <cameron.logie@×××××××××××.com>
Cc: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Updating Snort Rules
Date: Thu, 06 May 2004 16:56:58
Message-Id: 25879.24.227.114.194.1083862567.squirrel@sqmail.homelinux.org
1 I just started using oinkmaster and popped it in a weekly cron as well,
2 but running as root. So far no problems. What permission problems were you
3 having?
4
5 So far, oinkmaster is working terrifically. I would recommend setting it
6 up. :)
7
8
9 > I too use oinkmaster on a weekly basis to download the current ruleset and
10 > roll in the changes.
11 > As long as you sort out your perms on the /etc/snort directory it's fine.
12 > I just run it from the snort users crontab.
13 >
14 > Regards,
15 > Cammy.
16 >
17 > --
18 > Cameron Logie - Rushbrook IT
19 > Internet | Systems | Security
20 > Linux solutions for forward thinkers
21 >
22 > [W] http://www.rushbrookit.com/
23 > [E] cameron.logie@×××××××××××.com
24 > [T] 0870 765 0620
25 >
26 > GPG Key fingerprint = F83F 9D7F 80FF 79A6 B36D 7C97 7491 5C03 7F2B 65D7
27 > Public Key at http://www.rushbrookit.com/gpgkeys/cameron.logie.gpg.asc
28 >
29 > Ryan said:
30 >> I just recently installed snort on a machine to watch my network. I see
31 >> that there are several scripts out there that support automatic updating
32 >> of the snort ruleset to keep it current. Could anyone recommend a
33 >> program
34 >> for doing that or comment on their experience with them? I'd just like
35 >> to
36 >> have some means of automatically downloading new rules and installing
37 >> them. Also, is there an "emerge snortrules" or some similar ebuild that
38 >> I've missed?
39 >>
40 >> Thanks,
41 >> Ryan
42 >>
43 >> --
44 >> gentoo-security@g.o mailing list
45 >>
46 >>
47 >>
48 >
49 >
50 > --
51 > gentoo-security@g.o mailing list
52 >
53 >
54
55
56 --
57
58
59 --
60 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Updating Snort Rules Phil Cryer <phil@×××××.us>