Re: [fw-wiz] stop microsoft p2p
From: Julian Gomez (kluivert@tm.net.my)
Date: 03/28/03
- Previous message: Sloane, David: "RE: [fw-wiz] stop microsoft p2p"
- In reply to: Bennett Todd: "Re: [fw-wiz] stop microsoft p2p"
- Next in thread: Sloane, David: "RE: [fw-wiz] stop microsoft p2p"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Julian Gomez <kluivert@tm.net.my> To: firewall-wizards@honor.icsalabs.com Date: Fri, 28 Mar 2003 12:25:41 +0800 (MYT)
On Thu, 27 Mar 2003, Bennett Todd wrote:
(snip rest)
> remotely, and there's no "connection" to drop. But maybe some of
> the ICMP tricks will work. Fortunately, designing robust protocols
> without the help of TCP is hard enough that few people try; an IPS
> can carry you a long way.
>
> If you want to play with the IPS approach, you could build snort
> with flexresp enabled and play with that.
Or you could try one of the tools from Dug Song's dsniff package, I used
to have quite some fun with it killing off non-compliant users which used
IM clients in the office :-)
But that was laborous, and to make it easier will probably mean Snort
again for most people, so snort+flexresp inbuilt would be easier than
tying it separately to an external program.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Sloane, David: "RE: [fw-wiz] stop microsoft p2p"
- In reply to: Bennett Todd: "Re: [fw-wiz] stop microsoft p2p"
- Next in thread: Sloane, David: "RE: [fw-wiz] stop microsoft p2p"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|