[Snort-sigs] Web Traffic Rule

Jason Haar Jason.Haar at ...651...
Wed Feb 13 16:42:42 EST 2008

Michael Wisniewski wrote:
> Hi!
> I need to monitor internet traffic with who goes to which URL and
> path. I've done a search here, and people say to use 'squid'. However,
> I already setup snort and would like to do other things with it in the
> future.
First off, if you are using a PIX firewall (or I imagine some other 
types), it can be configured to log (via syslog) all URLs, secondly 
dsniff contains 'urlsnarf' which will do exactly what you want.


Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

More information about the Snort-sigs mailing list