That could help me to invent my own rules. Thanks Rodrigo.

It seems that no one has any snort rules ready on this mailing list. And
by google searching I didn't find any rules either. So, when I have made
some rules and tested it, I will post them in the OSSEC wiki that others
have some rules for snort when they are searching for this.

Regards

Rodrigo Montoro(Sp0oKeR) wrote:
> Hi Andre,
>
> I wrote sometime ago this paper "Building an active response IDS with
> OSSEC/Snort"
>
> http://www.dynsec.com.br/arquivos/ossec-snort-activeresponse_english.pdf
>
> Hope it helps!
>
> Regards,
>
> On Wed, Jun 17, 2009 at 3:28 PM, Andre Pawlowski<[email protected]> wrote:
>   
>> Hi guys.
>>
>> I just installed snort and tested it. Now I had the idea to combine it
>> with ossec. So I read a little bit in the wiki and saw that the rules
>>
>> 20300 - 20499 IDS (Snort specific)
>>
>> are for snort. But I can't find them in the ossec/rules directory. I
>> used the latest stable version of ossec (ossec 2). Are there any rules
>> for the /var/log/snort/alert logfile? Has anyone of you ossec that take
>> a look to the snort logfiles running? Which log format I must enter in
>> the ossec.conf when I configure the position of the snort logfile?
>>
>> Thanks in advance.
>>
>> --
>>
>> Andre Pawlowski
>>
>> -------------------------------------------------------------------
>>
>> Amerikas Verbündete müssen bei jedem neuen Präsidenten lernen, was für die 
>> nächsten vier oder acht Jahre das Gute und das Böse ist - ein anstrengender 
>> Prozess.
>>        -Carl Friedrich von Weizsäcker
>>
>>
>>     
>
>
>
>   

-- 

Andre Pawlowski

-------------------------------------------------------------------

Man wird nur schlauer, wenn man gegen schlauere Gegner spielt.
        -Fundamentals of Chess

Reply via email to