[Snort-users] Limewire

rottz at ...1904... rottz at ...1904...
Wed Sep 5 17:06:17 EDT 2001


Joe Lawson wrote:
> 
> Greetings:
> 
> Has anyone captured a Limewire session and developed a Snort rule to detect
> this specific variant of Gnutella?
Check out policy.rules line 23-26 which are generic GNUTella connect
rules which catch all Limewire connections.

Do you really need to specify limewire from other gnutella clients?
If so, I have some packet captures which I could try to develop more
"specific" rules if you want.

Peter
-- 
rottz at securityflaw dot com
Founder of Securityflaw




More information about the Snort-users mailing list