[Snort-sigs] Web Traffic Rule

Michael Wisniewski wiz561 at ...2420...
Wed Feb 13 16:51:12 EST 2008


Hmmm....maybe I'll check out dsniff with urlsnarf.  I only have
limited resources to work with.  It's a long story, which I'm not
going to get into....but basically, I have to figure out a way to
monitor web and other ports.

BTW, I'll check out dsniff again.  I *think* I used it a LONG time
ago.  I'll have to check it out again.

Thanks!

On Feb 13, 2008 3:42 PM, Jason Haar <Jason.Haar at ...651...> wrote:
> Michael Wisniewski wrote:
> > Hi!
> >
> > I need to monitor internet traffic with who goes to which URL and
> > path. I've done a search here, and people say to use 'squid'. However,
> > I already setup snort and would like to do other things with it in the
> > future.
> >
> First off, if you are using a PIX firewall (or I imagine some other
> types), it can be configured to log (via syslog) all URLs, secondly
> dsniff contains 'urlsnarf' which will do exactly what you want.
>
>
> --
> Cheers
>
> Jason Haar
> Information Security Manager, Trimble Navigation Ltd.
> Phone: +64 3 9635 377 Fax: +64 3 9635 417
> PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
>
>
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Microsoft
> Defy all challenges. Microsoft(R) Visual Studio 2008.
> http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
>




More information about the Snort-sigs mailing list