[Snort-users] IM detection

Joel Esler joel.esler at ...1935...
Wed Jun 7 21:12:28 EDT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ensure you have chat.rules and policy.rules turned on in your IDS.
Either that, or your users have figured you out :)

J

fname lname wrote:
> For some reason my snort use to tell me users running im apps on the
> corp network.  But now it stopped not sure why.  what can I do to fix this?
> 
> 
> ------------------------------------------------------------------------
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users

- --
+---------------------------------------------------------------------+
Joel Esler  	     Senior Security Consultant 	1-706-627-2101
Sourcefire    Security for the /Real/ World -- http://www.sourcefire.com
Snort - Open Source Network IPS/IDS -- http://www.snort.org
GPG Key http://demo.sourcefire.com/jesler.pgp.key
+---------------------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFEh3ieKbCSyXHckt4RAi42AJ9q2w0/WjIZZed2P8NTbT5I64hNvACfdRoE
T671ehZG/s3sqZrHK0NDXOA=
=jO7C
-----END PGP SIGNATURE-----




More information about the Snort-users mailing list