Snort mailing list archives

Re: Hello


From: vishesh kumar <linuxtovishesh () gmail com>
Date: Fri, 2 Apr 2010 13:46:43 +0530

I want to create rule that alert me when any exe downloaded using http
from internet
Thanks

On 4/1/10, Mike Lococo <mikelococo () gmail com> wrote:
My query is i want to monitor exe downloads in my network, how can
i achieve that ?

The Emerging Threats project has sigs to monitor for win32 executable
downloads.  See the following post/thread:

http://lists.emergingthreats.net/pipermail/emerging-sigs/2009-August/003438.html

You should also really consider using a more descriptive subject line in
the future: http://www.catb.org/~esr/faqs/smart-questions.html

Cheers,
Mike Lococo

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


-- 
Sent from my mobile device

http://linuxinterviews.blogspot.com

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: