Snort mailing list archives
Rules for detecting spyware
From: "Marc Quibell" <mquibell () fbfs com>
Date: Mon, 11 Aug 2003 09:54:49 -0500
I've done a little checking, so far no luck. I wonder if it's possible to setup some Snort rules for detecting spyware data. I'll keep looking for the actual data content of such packets, but does anyone already have some rules? TIA! Marc ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Rules for detecting spyware Marc Quibell (Aug 11)
- Re: Rules for detecting spyware Brian (Aug 28)
- RE: Rules for detecting spyware Gordon Cunningham (Aug 28)
- RE: Rules for detecting spyware twig les (Aug 28)
- RE: Rules for detecting spyware Gordon Cunningham (Aug 28)
- <Possible follow-ups>
- RE: Rules for detecting spyware Zach Forsyth (Aug 29)
- RE: Rules for detecting spyware Marc Quibell (Aug 29)
- Re: Rules for detecting spyware Brian (Aug 28)