Snort mailing list archives

Spyware Wanted (Won't often see THIS subject)


From: "Bob Konigsberg" <bobkberg () networkeval com>
Date: Mon, 6 Dec 2004 09:49:16 -0800

I'm working with the BleedingSnort rules, but to do some additional testing,
I need to find sources on the web for various forms of spyware.

Gator/Gain/Claria is easy
180Solutions is easy, and so are some others

Many others are not - particularly because they're often mixed together on
any given machine, and all running.

The objective here is to start with a clean Vmware based windows machine
(virtual hard disk copied from a CD-ROM image), and infect it with one at a
time (or as close as I can get), and then watch with a sniffer to tune and
build new rules.

As an aside, I've been having a lot of fun with the rules already submitted
by all these other folks.

Thanks,

Bob Konigsberg
Network Evaluation (We're Looking For Trouble)
(408) 395-3921 (Office)
(408) 839-8464 (Cell)
"The only reason anyone has a job is because someone else has a problem.
What are YOU doing to solve that problem?"
 


Current thread: