|
Re: P0F in Snort?: msg#00158security.ids.snort.bleedingsnort
The only problem I can think of off the top of my head is that certain firewalls (openbsd comes to mind) do packet normalization which defeats p0f. So if someone was going to work on this I would suggest taking p0f information with a grain of salt. -Blake Matt Jonkman wrote: Stray thought: ANyone ever seen or thought about integrating p0f into -- Blake Matheny bmatheny-YBzcoN68hchIf6P1QZMOBw@xxxxxxxxxxxxxxxx http://mobocracy.net |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | DNS Query sigs: 00158, Matt Jonkman |
|---|---|
| Next by Date: | Re: P0F in Snort?: 00158, Matt Jonkman |
| Previous by Thread: | Re: P0F in Snort?i: 00158, Martin Holste |
| Next by Thread: | Re: P0F in Snort?: 00158, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |