Re: snort_ddos.rules and snort_dos.rules
Joel Esler via Snort-sigs <[email protected]> Thu, 18 Jan 2024 17:34:56 -0500
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
Yes. In fact, I depreciated them when I was still at Sourcefire (before we were purchased by Cisco!). There hasn't been anything in those categories for years. If you want DDOS/DOS rules, you need to look at the classification in the rules for denial-of-service. https://blog.snort.org/2012/03/rule-category-reorganization.html https://blog.snort.org/2012/08/rule-category-reorganization-phase-2.html > On Jan 17, 2024, at 06:40, Patrick Ambühl via Snort-sigs <[email protected]> wrote: > > > Are these two rules deprecated ? I see them as options if Snort/PFSense but when enabled no rules are displayed (active or disabled). I also checked the snortrules-snapshot-31470.tar.gz and could not find these rules either. > > > Thank you > > Patrick > _______________________________________________ > Snort-sigs mailing list > [email protected] > https://lists.snort.org/mailman/listinfo/snort-sigs > > Please visit http://blog.snort.org for the latest news about Snort! > > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette > > Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>! _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!