honeyd ruleset for prelude-lml

Bjoern Weiland <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
Hey guys,

I am currently working on a new version of honeyd.rules, which should
apply to all honeyd versions since 0.7 or 0.8 (as the current version is
only working with very early honeyd releases). It is basically already
done, I just gotta combine my files. I will be posting it next week to
this mailinglist for consideration.
If there is anybody currently working on this, too, please contact me,
so that we can merge our efforts.
As my honeyd is not unsing the full power it comes with (e.g. no
subsystems), maybe there are some logentries missing in my honeyd.rules.
In that case, it's gotta be tweaked, so if there are some honeyd users
out there, I will need your help with some extra logentries to trigger.

More to come next week,

 -so long, bjoern

PS: Niels Provos (developer of honeyd) assured me, that there are no
plans to change the logformat again, so this should do it for a while I
guess.
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.