]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blobdiff - config/snort/snort.conf
Den Nettraffic Buildprozess bearbeitet.
[people/pmueller/ipfire-2.x.git] / config / snort / snort.conf
index 7e2a951e647c157b65f695381eeb9679432c8973..5d35d07c4dbdae71060ab41cc22a29029b9d8853 100644 (file)
@@ -21,6 +21,7 @@ var HTTP_SERVERS    $HOME_NET
 var SQL_SERVERS     $HOME_NET
 var TELNET_SERVERS  $HOME_NET
 var HTTP_PORTS      80
+var SSH_PORTS       22 222
 var SHELLCODE_PORTS !80
 var ORACLE_PORTS    1521
 var AIM_SERVERS     [64.12.24.0/24,64.12.25.0/24,64.12.26.14/24,64.12.28.0/24,64.12.29.0/24,64.12.161.0/24,64.12.163.0/24,205.188.5.0/24,205.188.9.0/24]
@@ -65,21 +66,14 @@ preprocessor flow-portscan: \
        alert-mode once \
        output-mode msg \
        tcp-penalties on
-preprocessor xlink2state: ports { 25 691 }
 #=========================================
 include $RULE_PATH/classification.config
 include $RULE_PATH/reference.config
 #=========================================
 include $RULE_PATH/bleeding-attack_response.rules
-include $RULE_PATH/bleeding-botcc-BLOCK.rules
-include $RULE_PATH/bleeding-botcc.excluded
 include $RULE_PATH/bleeding-botcc.rules
-include $RULE_PATH/bleeding-botcc.rules.dragon.xml
 include $RULE_PATH/bleeding-dos.rules
-include $RULE_PATH/bleeding-drop-BLOCK.rules
 include $RULE_PATH/bleeding-drop.rules
-include $RULE_PATH/bleeding-drop.rules.dragon.xml
-include $RULE_PATH/bleeding-dshield-BLOCK.rules
 include $RULE_PATH/bleeding-dshield.rules
 include $RULE_PATH/bleeding-exploit.rules
 include $RULE_PATH/bleeding-game.rules
@@ -88,7 +82,6 @@ include $RULE_PATH/bleeding-malware.rules
 include $RULE_PATH/bleeding-p2p.rules
 include $RULE_PATH/bleeding-policy.rules
 include $RULE_PATH/bleeding-scan.rules
-include $RULE_PATH/bleeding-sid-msg.map
 include $RULE_PATH/bleeding-virus.rules
 include $RULE_PATH/bleeding-voip.rules
 include $RULE_PATH/bleeding-web.rules
@@ -107,7 +100,6 @@ include $RULE_PATH/community-misc.rules
 include $RULE_PATH/community-nntp.rules
 include $RULE_PATH/community-oracle.rules
 include $RULE_PATH/community-policy.rules
-include $RULE_PATH/community-sid-msg.map
 include $RULE_PATH/community-sip.rules
 include $RULE_PATH/community-smtp.rules
 include $RULE_PATH/community-sql-injection.rules