Snort mailing list archives

Re: As virus.rules works??


From: Erek Adams <erek () theadamsfamily net>
Date: Tue, 5 Mar 2002 14:31:56 -0800 (PST)

On Tue, 5 Mar 2002, Jhon Cesar Arango wrote:

somebody can indicate to me as this option works, that happens when a virus
detects: it creates log or it eliminates the virus and it makes a report via
email?

It works the same as any of the other rules.  It sends an alert to your output
(specified in snort.conf) and logs the packet.

If you are wanting something to do inbound/outbound email virus scanning, this
isn't it.  Sophos and some others do this.  Try a google search on 'email
virus scanners' and see what you get.

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: