[Snort-sigs] Snort Rule Howto

Andrews Carl 448 Carl.Andrews at ...2744...
Thu Aug 19 12:11:17 EDT 2004


Hi! If anyone can help, it would be much appreciated. 
I need to write a rule(s) to block certain types of files from crossing the
network to/from a computer. For instance, I would like to use the FLEXRESP
option to terminate a connection if and EXE,DLL,ZIP, etc is copied to or
from this server. My goal is to setup a server for web proxying that does
not allow anything even remotely executable to pass through it. I have
searched and have not found any viable proxy server software that does mime
type filtering.
Thanks in advance,
Carl
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20040819/72b57363/attachment.html>


More information about the Snort-sigs mailing list