public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: "Erik K." <ummeegge@ipfire.org>
To: development@lists.ipfire.org
Subject: Re: Update for Snort and daq
Date: Thu, 01 Nov 2012 20:28:36 +0100	[thread overview]
Message-ID: <62F9B174-A6BC-4393-9D16-46517F51C4F1@ipfire.org> (raw)
In-Reply-To: <1351788773.19247.245.camel@rice-oxley.tremer.info>

[-- Attachment #1: Type: text/plain, Size: 1559 bytes --]

Hi Michael,
i have tested some ICMP and Shellcode rules. The rules needs to be activated for special purposes by clicking the category and selecting the specifics. The test has been done with the VRT sourcefire rules (for registrated users) so far the alerts are working and they are also displayed by the WUI. But i think it is important that more testing environments go for a checkout.
Also i have checked the logs for specific warnings and errors and i haven´t found some errors or heavily warnings only some old well known messages which doesn´t constrain the functionality of Snort.

But as i said the more people are testing the better it is

Erik

Am 01.11.2012 um 17:52 schrieb Michael Tremer:

> Hey,
> 
> I would love to see some people testing this, because snort is scheduled
> for the next core update.
> 
> Arne is going to merge this soon and so I guess that there will be a few
> days until this appears in the testing tree.
> 
> Michael
> 
> On Thu, 2012-11-01 at 17:16 +0100, Erik K. wrote:
>> Hi all,
>> i want to inform you that i have commit an update to the latest version of Snort 2.9.3.1 and also of daq 1.1.1 .  There has been a lot of changes for example the configuration file from Snort has been changed, also there are a couple of new rules contained and some more. Patches and an .iso Image with both updates can be found in the Bugtracker --> https://bugzilla.ipfire.org/show_bug.cgi?id=10255
>> 
>> Please test it and leave some feedback.
>> 
>> Thanks and greetings
>> 
>> Erik
>> 
>> 
> 


  reply	other threads:[~2012-11-01 19:28 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-11-01 16:16 Erik K.
2012-11-01 16:52 ` Michael Tremer
2012-11-01 19:28   ` Erik K. [this message]
2012-11-03 13:51     ` Stefan Schantl
2012-11-02 11:36 ` arne_f

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=62F9B174-A6BC-4393-9D16-46517F51C4F1@ipfire.org \
    --to=ummeegge@ipfire.org \
    --cc=development@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox