OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Snort-users] Snort inline timeout

From: Frank Knobbe (frankknobbe.us)
Date: Thu Jul 30 2009 - 15:05:00 CDT


On Thu, 2009-07-30 at 12:28 -0400, Joel Esler wrote:
> Snortsam is an "after attack" enforcement system. Snort inline deals
> with the attack during.

I take offense with that statement :)

Snortsam is an "after packet" enforcement system, while Snort Inline
deals with the packets.

Snortsam is well suited to stop brute force attacks. But the initial
packet or packets (however many required for the signature to fire) will
go through.

Cheers,
Frank

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.10 (FreeBSD)

iD8DBQBKcfzspIc56HlJ1YARAhUxAKCTYmgJ/mmyjzOV6fSE7hwwBi9REACfRsr8
hwH1zvuDQQmpsSVFqehDnAw=
=7LYz
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
trial. Simplify your report design, integration and deployment - and focus on
what you do best, core application coding. Discover what's new with
Crystal Reports now. http://p.sf.net/sfu/bobj-july

_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users