Re: how to test free Registered rules

Ivan Radev <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CAKEGQ22CBTZoKxWpn2T2tUwe=-Utk0N14qEpXYpZSF+UZxhhjg@mail.gmail.com>
Hello Lolita,
This is not a straightforward question as the set of rules is constantly
changing. You can give a try testing your IDS/IPS with a vulnerability
assessment tool as OpenVAS, Qualys, or just craft rules for yourself and
then craft packets that match. Basic example is to create a simple icmp
rule with a content matcher, then ping with a pattern "ping -p" . The
pattern uses only hexa.
Cheers, Ivan

<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail&utm_term=icon>
Virus-free.
www.avast.com
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail&utm_term=link>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>

On Mon, Mar 22, 2021 at 3:18 PM Lolita M. via Snort-sigs <
[email protected]> wrote:

> Hello. I’m Laurie. I’m new to snort. I configure yet my detector and i
> think all things is rigth ; I got the message "Snort successfuly validated
> the configuration ». Now i want to truly test an intrusion detection with
> my free Registered rules - Downloaded on the site-.
>
> Which tests can i make ? How make these tests ? May i get all details
> possible ?
>
>
>
> Thank you
>
>
>
>
> _______________________________________________
> Snort-sigs mailing list
> [email protected]
> https://lists.snort.org/mailman/listinfo/snort-sigs
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>
> Visit the Snort.org to subscribe to the official Snort ruleset, make sure
> to stay up to date to catch the most <a href="
> https://snort.org/downloads/#rule-downloads">emerging threats</a>!
>


-- 
Ivan Radev
TechnoCore

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.