
NETWORK SECURITY TACTICS
How to decipher the Oinkcode for Snort's VRT rules
JP Vossen, CISSP 05.05.2005
Rating: --- (out of 5)




|
Sourcefire has changed the licensing and distribution of Snort rules, and created the VRT Certified rules, which are tested and certified by the Sourcefire Vulnerability Research Team.
As an end user, you can get these rules in one of three ways:
There are special considerations if you are a "Snort Integrator." In any case, you need to read the FAQ at Snort.org.
If your organization is a Snort end user, you will almost certainly want to register for free and generate an Oinkcode, which will allow you to download the VRT rules. Once you have read and understood the FAQ, create an account at Snort.org and log in. At the bottom of the Account Settings page you will find a button to generate an Oinkcode, along with instructions for conf
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

iguring your oinkmaster.conf, if you are using Oinkmaster. But even if you are not, the URL you construct (such as http://www.snort.org/pub-bin/oinkmaster.cgi/5a081649c06a277e1022e1284bdc8fabda70e2a4/snortrules-snapshot-2.3.tar.gz) may be bookmarked in a browser or used with wget or some other
download tool to download the rules.
Your Oinkcode for VRT Certified rules will look like this:
http://www.snort.org/pub-bin/oinkmaster.cgi//
Example for snort 2.3:
http://www.snort.org/pub-bin/oinkmaster.cgi/5a081649c06a277e1022e1284bdc8fabda70e2a4/snortrules-snapshot-2.3.tar.gz
You can also get GPL community rules (free, no registration or Oinkcode required, very limited) from Snort.org
[TABLE]
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |