Snort mailing list archives

Rule for dropping packets


From: santhoj san <santhojirulappan () gmail com>
Date: Wed, 21 Oct 2015 18:11:41 +0530

Hi all,

Greetings.

I have configured and installed snort. I need to block some application
packets like skype, youtube, firefox etc. I have used
"drop tcp any any -> any any (msg:"No skype"; appid:skype; sid:10000004;
rev:001; )" and similar for youtube.
But still I'm able to login to skype, make IM and calls, see youtube videos.

Can anyone please help me in writing a snort rule for dropping the specific
application packets like youtube, firefox, skype etc.

Thank you in Advance.

Regards
Santhoj Irulappan
------------------------------------------------------------------------------
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: