[Snort-users] As virus.rules works??

Erek Adams erek at ...577...
Tue Mar 5 14:33:02 EST 2002

On Tue, 5 Mar 2002, Jhon Cesar Arango wrote:

> somebody can indicate to me as this option works, that happens when a virus
> detects: it creates log or it eliminates the virus and it makes a report via
> email?

It works the same as any of the other rules.  It sends an alert to your output
(specified in snort.conf) and logs the packet.

If you are wanting something to do inbound/outbound email virus scanning, this
isn't it.  Sophos and some others do this.  Try a google search on 'email
virus scanners' and see what you get.

Erek Adams

More information about the Snort-users mailing list