Snort mailing list archives

Re: Anti Virus on Linux?


From: Bob McClure Jr <robertmcclure () earthlink net>
Date: Mon, 27 Jan 2003 15:20:37 -0600

On Mon, Jan 27, 2003 at 03:57:02PM -0500, Paul Greene wrote:
I would also disagree that there's no point in scanning outgoing mail. 
Aren't there laptop users that bring their laptops in from the outside, 
and have had opportunities to bring in viruses that haven't gone through 
the corporate firewalls and e-mail servers?

pg

Sean T. Ballard wrote:

It's also true that some of the customers use outside email accounts
like hotmail and such, which is another hole.  Now let me be more
specific.

It was fairly simple for me to wire it into the incoming side, but for
the outgoing side, it would have required rebuilding sendmail so I
could wire in the Milter interface, and then hook the stuff in there.

But the proof is in the pudding.  Out of a customer base of 850 or so,
we used to get two or three victims a week.  With the incoming filter
in place for the last six months or so, only one customer has gotten
infected.

The cost-to-benefit ratio looks pretty good to me.

Cheers,
-- 
Bob McClure, Jr.             Bobcat Open Systems, Inc.
robertmcclure () earthlink net  http://www.cumbytel.com/~bobcatos/
Peace at any price is inflationary.


-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: