[Snort-users] Snort rules: TOR Servers

Joel Esler jesler at ...1935...
Thu Feb 7 23:32:00 EST 2013

On Feb 7, 2013, at 11:20 PM, David Cottam <cot07001 at ...16087...> wrote:

> Hello,
> I am configuring a snort server and am looking for a good way to detect what torrent servers are being accessed and perhaps block them.  I have not been able to find anything useful online.
> Who can help me with TOR rules?

We have the TOR exit nodes in our blacklist technology which you can use the IP reputation preprocessor to load up.

The feed is here:

The next release of Pulledpork (or the one in svn right now) has this built in.

Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager

More information about the Snort-users mailing list