Snort mailing list archives

OT E-mail Viruses


From: "Madziarczyk, Jonathan" <than () cityofevanston org>
Date: Fri, 14 Jun 2002 10:39:34 -0500

Hey all,
 
  So I've got my snort rules set up to alert on possible Klez Viruses (as
well as other e-mail transferred viruses, like Code Red, etc).  That seems
to be working pretty well.  As expected, I do seem to be missing some resets
via flexresp and I'd prefer not to use it anyway just to avoid blocking
false positives.  Is there a product out there that works well at blocking
inbound/outbound viruses on e-mail?  I'm trying to find something that works
on both straight SMTP (unix and listservs) and ESMTP (Exchange).  So what do
the experts (you) recommend?
 
Hopefully this e-mail won't get anyone drunk today. ;-p
 
Peace,
JonM

Current thread: