Snort mailing list archives
Spyware Wanted (Won't often see THIS subject)
From: "Bob Konigsberg" <bobkberg () networkeval com>
Date: Mon, 6 Dec 2004 09:49:16 -0800
I'm working with the BleedingSnort rules, but to do some additional testing, I need to find sources on the web for various forms of spyware. Gator/Gain/Claria is easy 180Solutions is easy, and so are some others Many others are not - particularly because they're often mixed together on any given machine, and all running. The objective here is to start with a clean Vmware based windows machine (virtual hard disk copied from a CD-ROM image), and infect it with one at a time (or as close as I can get), and then watch with a sniffer to tune and build new rules. As an aside, I've been having a lot of fun with the rules already submitted by all these other folks. Thanks, Bob Konigsberg Network Evaluation (We're Looking For Trouble) (408) 395-3921 (Office) (408) 839-8464 (Cell) "The only reason anyone has a job is because someone else has a problem. What are YOU doing to solve that problem?"
Current thread:
- Spyware Wanted (Won't often see THIS subject) Bob Konigsberg (Dec 06)
