Re: IDS for old box?

From: Rowdy Yates (rowdy.yates_at_no-spam.lycos.com)
Date: 01/07/04

  • Next message: phn_at_icke-reklam.ipsec.nu: "Re: hardware firewall"
    Date: Wed, 7 Jan 2004 14:06:42 GMT
    
    

    Jan Reilink <janreilink@vevida.nl> wrote in news:vvnubp5e2li324
    @corp.supernews.com:

    > sponge wrote:
    >
    >> On 6 Jan 2004 13:13:24 +0100, SteveYiu@nospam.com wrote:
    >>
    >>>Anyone know an IDS program that will work on Win9x?
    >>>I know I know all about Win9x and yes I've applied the patches and
    >>>yes it's stable. I just want something extra besides my fw that will
    >>>inspect pkets against signatures, strings, etc.
    >>
    >> Snort. www.snort.org. It cannot do any kind of reactive IDS (Flexible
    >> Reponse), to shut down connections, on Win9x. You need either an NT
    >> derivative, Linux, or Unix.
    >
    > Trust me, one thing you don't want is an active (N)IDS [1], it just
    > doesn't work! You are always behind on signatures, so the chance is
    > relatively high you miss intrusions. Passive (N)IDS, like Snort, is the
    > way to go.
    >
    > [1] An active (N)IDS will add firewall rules to block connections, for
    > instance. Passive (N)IDS only logs connections for examination.
    >

    interesting opinion.

    -- 
    Rowdy Yates
    MCSE, Security+, Linux+
    

  • Next message: phn_at_icke-reklam.ipsec.nu: "Re: hardware firewall"

    Relevant Pages

    • Re: Linux (Suse) TS ?
      ... I'd need to run secure connections back to the corporate network. ... > knoppix cd's, the various thin client linux distros, the LTSP project etc ... this first step display updates were alright, ... have their data volume on your server. ...
      (alt.os.linux.suse)
    • Re: Sharing a Share ?
      ... are too MANY users and access to the shared drives blocked. ... A partial solution seems to lie in linux. ... I created a Samba ... So using your Linux box to multiplex indirect connections is a no-no. ...
      (alt.linux)
    • Re: Questions about using two Satelite uplinks
      ... Set up linux on ... connections. ... The other two NICs, eth3 ... The Hughes Net tech support guy seems to ...
      (comp.os.linux.misc)
    • Re: SSL LDAP intermittent failure to bind
      ... server and the linux box running PHP is pulling from it as well. ... three domain controllers are pulling time from the Domain Hierarchy and sync ... that blocks LDAP\SSL connections if it gets bombarded with requests? ... connecting from a linux machine to ldap over ssl using a Domain Controller ...
      (microsoft.public.windows.server.active_directory)
    • Re: Sharing a Share ?
      ... are too MANY users and access to the shared drives blocked. ... A partial solution seems to lie in linux. ... I created a Samba ... The ten connection maximum /includes any indirect connections made through "multiplexing"/ or other software or hardware which pools or aggregates connections... ...
      (alt.linux)