Re: snort for ipcop 2.x
David W Studeman <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.devel |
|---|---|
| Message-ID | <[email protected]> |
John Edwards wrote: > Hi > > On Wed, May 09, 2012 at 06:41:52AM -0700, Necip Celepci wrote: >> hi, >> Is there a snort plugin for IPCop 2.x >> Thank you. > > Not in the main distribution. I believe it has become too difficult > to maintain as Snort kept making it harder to get rule updates for > old versions. > > But a search on Google: > https://www.google.co.uk/search?hl=en&output=search&sclient=psy-ab&q=snort+plugin+for+IPCop+2.x&btnG=&gbv=1&sei=8HWqT9umNeSi4gT2zYiDCQ > > shows this results: > http://www.ipcops.com/phpbb3/viewtopic.php?f=7&t=17154 > > The ipcops.com forums are well know, but you should still be > careful about downloading and running code from the Internet. > > Also read the comment by Dave (of RaqCop) that shows you will > still need to do some work yourself to keep it updated. > > The creation of the addon was inevitable as there are people who don't think they can live without Snort, not the least of which is the author of the addon. Hopefully, he'll get it polished up and include more languages so it is usable by Snort devotees that insist on having Snort. As far as the reasons why the developers did not include it is well covered in this list a few years back but yeah, it would be a pain to maintain it. Other reasons are in line with my own reasons not to use it. False positives, high memory usage and so on. Basically extra noise that clouds the ability to see in a nutshell what's really happening at the firewall. I'm curious to see how well the folks do if they enable the inline (active) option with the full ruleset as downloaded directly from Snort. Anyone care to bet on how many pissed off internet users result from this option? -- Dave Studeman http:/www.raqcop.com ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/