[Snort-users] Kazaa P2P Rules

Allan Dover allan at ...8825...
Tue Apr 22 10:09:47 EDT 2003


Hey Erek and Gang,

I tried using the P2P rules, to catch Kazaa users on my network.  When using the p2p rules i see allot of port 25 activity for mail. usually a P2P Get command.  Anyone know a way of addressing Kazaa and Bearshare to be monitored/triggered in Snort.


Allan Dover
Systems Administrator
 
###################################################
This e-mail communication (including any or all attachments) is intended only for the use of the person or entity to which it is addressed and may contain confidential and/or privileged material. If you are not the intended recipient of this e-mail, any use, review, retransmission, distribution, dissemination, copying, printing, or other use of, or taking of any action in reliance upon this e-mail, is strictly prohibited. If you have received this e-mail in error, please contact the sender and delete the original and any copy of this e-mail and any  printout thereof, immediately. Your co-operation is appreciated. 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20030422/14969d52/attachment.html>


More information about the Snort-users mailing list