[Snort-sigs] Snort Rule Howto

twebster at ...2725... twebster at ...2725...
Thu Aug 19 13:34:50 EDT 2004




Dansguardian will do mime filtering.

www.dansguardian.org

tony

snort-sigs-admin at lists.sourceforge.net wrote on 08/19/2004 01:09:56 PM:

> Hi! If anyone can help, it would be much appreciated.
> I need to write a rule(s) to block certain types of files from
> crossing the network to/from a computer. For instance, I would like
> to use the FLEXRESP option to terminate a connection if and EXE,DLL,
> ZIP, etc is copied to or from this server. My goal is to setup a
> server for web proxying that does not allow anything even remotely
> executable to pass through it. I have searched and have not found
> any viable proxy server software that does mime type filtering.
> Thanks in advance,
> Carl





More information about the Snort-sigs mailing list