Koozali.org: home of the SME Server

updating S/A/G

Steve

updating S/A/G
« on: November 15, 2002, 04:06:16 AM »
Does anyone know how to update the Snort triggers/rules?  (Also listed as /etc/snort/*.rules)  I'm sure there are new exploits that snort doesn't have in its database.  I'm using this with Acid/Guardian also.  Are there any websites that you can download updated rules along with .conf file and just copy it?

Thanks!

Steve

Abe Loveless

Re: updating S/A/G
« Reply #1 on: November 26, 2002, 07:03:26 AM »
I would also be interested in this.  You can download the new rules from here.  But, I don't know if you can just dump the new rules in the directory or not.

http://www.snort.org/dl/

I tried installing the new snort rpm from the above site, but it didn't work quite right with the ACID contrib... the db didn't get updated, so ACID didn't display any results.