Snort mailing list archives

Re: blocking


From: Martin Forest <martin () heimdalls co nz>
Date: Fri, 17 May 2002 16:01:32 +1200

If you are using iptables you can setup a rule with content checking in iptables.
/Martin

Ganu Skop wrote:

hi all,
i believe this thought has been posted before.
anyway, what i'm looking is to block all the "cmd.exe"
coming to my network. i've heard guardian works fine
with ipchain , and snortsam with pix. is there any utility / script that works with ipf or
pf ?
thanks


=====
//skopganu

__________________________________________________
Do You Yahoo!?
LAUNCH - Your Yahoo! Music Experience
http://launch.yahoo.com

_______________________________________________________________

Have big pipes? SourceForge.net is looking for download mirrors. We supply
the hardware. You get the recognition. Email Us: bandwidth () sourceforge net
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





_______________________________________________________________

Have big pipes? SourceForge.net is looking for download mirrors. We supply
the hardware. You get the recognition. Email Us: bandwidth () sourceforge net
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: