[Snort-users] Snort rules: TOR Servers

Joel Esler jesler at ...1935...
Thu Feb 7 23:32:00 EST 2013


On Feb 7, 2013, at 11:20 PM, David Cottam <cot07001 at ...16087...> wrote:

> Hello,
> I am configuring a snort server and am looking for a good way to detect what torrent servers are being accessed and perhaps block them.  I have not been able to find anything useful online.
> 
> Who can help me with TOR rules?

We have the TOR exit nodes in our blacklist technology which you can use the IP reputation preprocessor to load up.

The feed is here:
http://labs.snort.org/feeds/ip-filter.blf

The next release of Pulledpork (or the one in svn right now) has this built in.

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire



More information about the Snort-users mailing list