Re: snort for ipcop 2.x

David W Studeman <[email protected]>
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <[email protected]>
John Edwards wrote:
> Hi
>
> On Wed, May 09, 2012 at 06:41:52AM -0700, Necip Celepci wrote:
>> hi,
>> Is there a snort plugin for IPCop 2.x
>> Thank you.
>
> Not in the main distribution. I believe it has become too difficult
> to maintain as Snort kept making it harder to get rule updates for
> old versions.
>
> But a search on Google:
> 	https://www.google.co.uk/search?hl=en&output=search&sclient=psy-ab&q=snort+plugin+for+IPCop+2.x&btnG=&gbv=1&sei=8HWqT9umNeSi4gT2zYiDCQ
>
> shows this results:
> 	http://www.ipcops.com/phpbb3/viewtopic.php?f=7&t=17154
>
> The ipcops.com forums are well know, but you should still be
> careful about downloading and running code from the Internet.
>
> Also read the comment by Dave (of RaqCop) that shows you will
> still need to do some work yourself to keep it updated.
>
>
  The creation of the addon was inevitable as there are people who don't 
think they can live without Snort, not the least of which is the author 
of the addon. Hopefully, he'll get it polished up and include more 
languages so it is usable by Snort devotees that insist on having Snort. 
As far as the reasons why the developers did not include it is well 
covered in this list a few years back but yeah, it would be a pain to 
maintain it. Other reasons are in line with my own reasons not to use 
it. False positives, high memory usage and so on. Basically extra noise 
that clouds the ability to see in a nutshell what's really happening at 
the firewall.

  I'm curious to see how well the folks do if they enable the inline 
(active) option with the full ruleset as downloaded directly from Snort. 
Anyone care to bet on how many pissed off internet users result from 
this option?


-- 
Dave Studeman
http:/www.raqcop.com


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.