[Snort-sigs] Rule for dropping packets

santhoj san santhojirulappan at ...2420...
Wed Oct 21 08:41:41 EDT 2015


Hi all,

Greetings.

I have configured and installed snort. I need to block some application
packets like skype, youtube, firefox etc. I have used
"drop tcp any any -> any any (msg:"No skype"; appid:skype; sid:10000004;
rev:001; )" and similar for youtube.
But still I'm able to login to skype, make IM and calls, see youtube videos.

Can anyone please help me in writing a snort rule for dropping the specific
application packets like youtube, firefox, skype etc.

Thank you in Advance.

Regards
Santhoj Irulappan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20151021/290fa515/attachment.html>


More information about the Snort-sigs mailing list