[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bro
Subject:    [Bro] IPS Functionality in  BRO
From:       "Anandraj" <anandrajm () fastmail ! fm>
Date:       2006-08-01 15:59:57
Message-ID: 1154447997.28228.267383104 () webmail ! messagingengine ! com
[Download RAW message or body]

Hi,
I was just goin through the BRO USER Manual and Found that BRO does some
amount of Prevention .
I did try "IPS" by adding the following in hot.bro .

const terminate_successful_inbound_service: table[port] of string = {
              [22/tcp] = "SSH",
} &redef;

also i did change the ssh.bro to the following .

redef restrict_filters += { ["ssh"] = "port 22" };

But in vain , i could NOT prevent the ssh traffic.
I was able to ssh to other machines and also other machines were able to
ssh to my machine.

Could somebody shed some light on this?
Any pointers about the BRO with IPS would be really helpful .

Thanks,
Anand




-- 
http://www.fastmail.fm - Access all of your messages and folders
                          wherever you are


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic