Re: Vulnerability & Exploit Signatures

From: Matt Jonkman (matt_at_infotex.com)
Date: 06/16/05

  • Next message: MadHat: "Re: Vulnerability & Exploit Signatures"
    Date: Thu, 16 Jun 2005 10:31:19 -0500
    To: Kelly Dowd <loris65@gmail.com>
    
    

    <shameless plug>

    Also consider the Bleeding Edge Snort project (www.bleedingsnort.com)

    Our sigs are from the community and BSD licensed. So they are free for
    use in commercial products, we just hope companies using them will
    contribute back to the community and mention to their customers that
    some of their sigs come from us.

    We do have many commercial products using these sigs, and most of the
    firms we're aware of are very active in the security community and the
    bleeding snort community. Some of those firms are sponsors of our
    project. Any others are welcome to become sponsors as well.

    Despite our warnings that the sigs are crude or unpolished, any problems
    are worked out within minutes, usually before posting even.

    </shameless plug>

    Matt

    Kelly Dowd wrote:
    > I doubt there is any licensing of base signatures between vendors
    > (signature engines vary greatly between products, you can't just 'use'
    > another products sigs). You will find that some developers look at
    > existing signature sets to get 'ideas', but it's far from a
    > one-for-one copy. Companies must develop their own sigs just like
    > they develop their own appliances... it's a total package.
    >
    > -Kelly D.
    >
    > On 6/14/05, Jackson Yu <jackson.yu@earthlink.net> wrote:
    >

    -- 
    --------------------------------------------
    Matthew Jonkman, CISSP
    Senior Security Engineer
    Infotex
    765-429-0398 Direct Anytime
    765-448-6847 Office
    866-679-5177 24x7 NOC
    my.infotex.com
    www.offsitefilter.com
    www.bleedingsnort.com
    --------------------------------------------
    NOTICE: The information contained in this email is confidential
    and intended solely for the intended recipient. Any use,
    distribution, transmittal or retransmittal of information
    contained in this email by persons who are not intended
    recipients may be a violation of law and is strictly prohibited.
    If you are not the intended recipient, please contact the sender
    and delete all copies.
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: MadHat: "Re: Vulnerability & Exploit Signatures"

    Relevant Pages

    • Re: Apology thread
      ... Jamieknox11 wrote: ... once again sorry everyone for being a disgrace to this community ... are you crazy ive got nothing agienst you but i think its a little bit ... crazy you just havnt removed the sigs. ...
      (rec.sport.unicycling)
    • [ANN] Do you run a Ruby user group, SIG, or conference?
      ... The Ruby Journal will feature a Community page dedicated to announcing Ruby events, user groups, SIGs, book and product releases, conferences, and more. ...
      (comp.lang.ruby)