Snort mailing list archives

RE: Rules for detecting spyware


From: "Marc Quibell" <mquibell () fbfs com>
Date: Fri, 29 Aug 2003 11:21:47 -0500



What the....? I wrote this message weeks ago! This thread still going...like the
Energizer Bunny! Neways, don't care much about detecting spyware on MY computer,
(me thinks we all know about adaware...etc) but would like to know how to detect
for the Enterprise, using Snort of course, just as it does with Kazaa...etc.

Naturally one would write rules for the varieties of spyware, was just wondering
if someone had done that yet. Thanks!

Marc


--Original Message--
Message: 2
From: "Zach Forsyth" <Zach.Forsyth () kiandra com>
To: <snort-users () lists sourceforge net>
Date: Fri, 29 Aug 2003 09:22:57 +1000
Subject: RE: [Snort-users] Rules for detecting spyware

I have found that spybot works a lot better than adaware.
It consistently finds more malware, spyware etc than adaware...

Spybot
http://www.safer-networking.org/


Adaware
http://www.lavasoftusa.com/


Just grab them both and try them out on the same machine.

Cheers

z




-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: