Re: [Snort-sigs] [Snort-users] Snort HTTPS
পথিক via Snort-devel <[email protected]> Thu, 14 Mar 2019 17:00:08 +0600
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <CAA+QOitxjR4=uEhbkmvfyupqoAo62cWQLo+dVz+YxXRgvLpimg@mail.gmail.com> |
HIDS can do before encryption and after decryptio. Motashim Al Razi. On Wed, 13 Mar 2019, 8:19 pm Kai Chan via Snort-sigs, < [email protected]> wrote: > Thanks for clarifying. > > Thanks, > Kai > > > On Tue, Mar 12, 2019, 4:34 PM Joel Esler (jesler) <[email protected]> > wrote: > >> >> >> > On Mar 12, 2019, at 4:17 PM, Kai Chan via Snort-users < >> [email protected]> wrote: >> > >> > Can Snort monitor HTTPS sessions, not just the handshake? >> >> It can monitor the handshake, however, not much is useful after that, as >> it would be encrypted. >> >> >> > Do you have to pay for rule subscriptions to get this? >> >> >> No, you'd have to have something decrypting the traffic before it reaches >> Snort. >> >> -- >> Joel Esler >> Manager, Communities Division >> Cisco Talos Intelligence Group >> http://www.talosintelligence.com > > _______________________________________________ > Snort-sigs mailing list > [email protected] > https://lists.snort.org/mailman/listinfo/snort-sigs > > Please visit http://blog.snort.org for the latest news about Snort! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > Visit the Snort.org to subscribe to the official Snort ruleset, make sure > to stay up to date to catch the most <a href=" > https://snort.org/downloads/#rule-downloads">emerging threats</a>! > _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort!