[Snort-sigs] Snort Rule Howto

John Hally JHally at ...1106...
Thu Aug 19 13:37:09 EDT 2004

I thought squid would allow you to strip out exe/dll/zip files.  Could be
wrong though.



From: snort-sigs-admin at lists.sourceforge.net
[mailto:snort-sigs-admin at lists.sourceforge.net] On Behalf Of Andrews Carl
Sent: Thursday, August 19, 2004 3:10 PM
To: snort-sigs at lists.sourceforge.net
Subject: [Snort-sigs] Snort Rule Howto


Hi! If anyone can help, it would be much appreciated. 
I need to write a rule(s) to block certain types of files from crossing the
network to/from a computer. For instance, I would like to use the FLEXRESP
option to terminate a connection if and EXE,DLL,ZIP, etc is copied to or
from this server. My goal is to setup a server for web proxying that does
not allow anything even remotely executable to pass through it. I have
searched and have not found any viable proxy server software that does mime
type filtering.

Thanks in advance, 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20040819/1104751f/attachment.html>

More information about the Snort-sigs mailing list