Yeah, look for PSAD, it is a an addon for snort that modifies iptables
automaticly in run-time :-)

Oleg.

----- Original Message ----- 
From: "Mycroft" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, July 01, 2003 1:14 AM
Subject: Snort - iptables addon


> Hello,
> Have anyone heard of/used an snort add-on that could manage iptables
firewall
> in responce to a specific network events...like portscans or DOS attacks?
> I know once it's detected, snort is capable of blocking it, but i was
looking
> for more low-level approach to this issue, stopping the packets cold on IP
> level. I know i can use psad for such things, but again, i am looking for
an
> add-on, not a second IDS...which i would have to cripple in order to let
them
> live together. Googling for an answer doesn't help much.
> -- 
> Sincerely Yours,
> Vasiliev Michael
>
> NP: XMMS is not loaded.
>
>
> =================================================================
> To unsubscribe, send mail to [EMAIL PROTECTED] with
> the word "unsubscribe" in the message body, e.g., run the command
> echo unsubscribe | mail [EMAIL PROTECTED]
>
>



=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]

Reply via email to