[Snort-sigs] Web Traffic Rule
Jason.Haar at ...651...
Wed Feb 13 16:42:42 EST 2008
Michael Wisniewski wrote:
> I need to monitor internet traffic with who goes to which URL and
> path. I've done a search here, and people say to use 'squid'. However,
> I already setup snort and would like to do other things with it in the
First off, if you are using a PIX firewall (or I imagine some other
types), it can be configured to log (via syslog) all URLs, secondly
dsniff contains 'urlsnarf' which will do exactly what you want.
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
More information about the Snort-sigs