OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Matt Kettler (mkettler_at_evi-inc.com)
Date: Mon Jan 27 2003 - 17:16:57 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Well, I'll agree it's not strictly snort related, and the first post even
    acknowledges that, so I'll agree it's OT to some degree. I'll add an OT
    flag to the subject in light of that.

    Still, to some degree issues related to keeping your snort box secure from
    rootkit and/or worm infiltration are relevant. Usually a snort box is in a
    very good position on the network to engage in spoofing attacks, so a
    penetrated snort box is a very dangerous thing.

    The thread seems to have diverged into clearly off-topic discussions of
    scanning e-mail, but the original post was asking if it's
    important/relevant for a snort sensor to have such software.

    So it's not totally unrelated, and certainly snort-box-security discussions
    should not be regarded as unimportant or irrelevant to Snort and the
    snort-users community.

    At 02:15 PM 1/27/2003 -0800, twig les wrote:
    >Not to be the stick-in-the-mud but this thread doesn't
    >seem to have anything whatsoever to do with Snort.

    -------------------------------------------------------
    This SF.NET email is sponsored by:
    SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
    http://www.vasoftware.com
    _______________________________________________
    Snort-users mailing list
    Snort-userslists.sourceforge.net
    Go to this URL to change user options or unsubscribe:
    https://lists.sourceforge.net/lists/listinfo/snort-users
    Snort-users list archive:
    http://www.geocrawler.com/redir-sf.php3?list=snort-users