[Snort-sigs] RE: Snort Rule Howto

Andrews Carl 448 Carl.Andrews at ...2744...
Fri Aug 27 07:08:15 EDT 2004


Why do my questions not get posted? I am a member of the list.

-----Original Message-----
From: Andrews Carl 448 
Sent: Friday, August 20, 2004 12:30 PM
To: Andrews Carl 448; 'snort-sigs at lists.sourceforge.net'
Subject: RE: Snort Rule Howto




-----Original Message-----
From: Andrews Carl 448 
Sent: Thursday, August 19, 2004 2:10 PM
To: snort-sigs at lists.sourceforge.net
Subject: Snort Rule Howto


Hi! If anyone can help, it would be much appreciated. 
I need to write a rule(s) to block certain types of files from crossing the
network to/from a computer. For instance, I would like to use the FLEXRESP
option to terminate a connection if and EXE,DLL,ZIP, etc is copied to or
from this server. My goal is to setup a server for web proxying that does
not allow anything even remotely executable to pass through it. I have
searched and have not found any viable proxy server software that does mime
type filtering.
Thanks in advance,
Carl
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20040827/1d088510/attachment.html>


More information about the Snort-sigs mailing list