Re: IDS for old box?

From: Jan Reilink (janreilink_at_vevida.nl)
Date: 01/07/04


Date: Wed, 07 Jan 2004 13:21:35 +0100

sponge wrote:

> On 6 Jan 2004 13:13:24 +0100, SteveYiu@nospam.com wrote:
>
>>Anyone know an IDS program that will work on Win9x?
>>I know I know all about Win9x and yes I've applied the patches and
>>yes it's stable. I just want something extra besides my fw that will
>>inspect pkets against signatures, strings, etc.
>
> Snort. www.snort.org. It cannot do any kind of reactive IDS (Flexible
> Reponse), to shut down connections, on Win9x. You need either an NT
> derivative, Linux, or Unix.

Trust me, one thing you don't want is an active (N)IDS [1], it just
doesn't work! You are always behind on signatures, so the chance is
relatively high you miss intrusions. Passive (N)IDS, like Snort, is the
way to go.

[1] An active (N)IDS will add firewall rules to block connections, for
instance. Passive (N)IDS only logs connections for examination.

-- 
Met vriendelijke groet / Best regards,
Jan Reilink, VEVIDA Nederland BV
Postbus 329, 9700 AH GRONINGEN, +31(0)50 - 5492234


Relevant Pages

  • Re: IDS for old box?
    ... >> Reponse), to shut down connections, on Win9x. ... >> derivative, Linux, or Unix. ... Passive IDS only logs connections for examination. ...
    (comp.security.misc)
  • Re: Hilfe mein PC spinnt
    ... Thunderbird von mozilla.com) ... IE 6.0 sowie Outlook Express auf die neueste version ... Patches einspielen. ... aktuellen IE-/OjE-Versionen unter Win9x mit Windowsupdate ...
    (de.comp.hardware.misc)
  • Re: IDS for old box?
    ... > I know I know all about Win9x and yes I've applied the patches and ... Install Linux and Snort. ... Get your Geek Goodies! ...
    (comp.security.misc)
  • Re: IDS for old box?
    ... >I know I know all about Win9x and yes I've applied the patches and ... It cannot do any kind of reactive IDS (Flexible ... Reponse), to shut down connections, on Win9x. ... If you would be willing to go the Linux ...
    (comp.security.misc)
  • IDS for old box?
    ... Anyone know an IDS program that will work on Win9x? ... I know I know all about Win9x and yes I've applied the patches and ... inspect pkets against signatures, strings, etc. ...
    (comp.security.misc)

Quantcast