[Snort-users] ClamAV preprocessor

Jose Maria Lopez jkerouac at ...12346...
Sun Oct 10 07:04:24 EDT 2004


El jue, 07 de 10 de 2004 a las 15:51, Jackie Solomon escribió:
> Greetings,
> I am trying to find a way to detect users on our network that have 
> infected systems. We are a broadband ISP and need to be able to detect 
> these problems to take appropriate action to protect the network 
> bandwidth. Is there a procedure to incorporating ClamAV with Snort?
> 
> Thanks!
> Jackie Solomon

The last version of snort-inline that I have downloaded and
installed have a section in the config file for ClamAV, so
I suppose it should work. I don't know if the last version
of snort have the same funcionality.

-- 
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac at ...12346...
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"





More information about the Snort-users mailing list