Nebulus: No point in using the IDS to drop both sides of the connection, (Yes Snort will do this if the rule is written to do it and there is also a test facility that allows a message to be sent to the two machines I believe - I gotta look into that in a minute.....), since the client will assume it is dropped at the firewall and allow the alternative connection to take place.
I'm gonna take a look at the message thingy, test it and see what it does. The I might add the message part to a rule for these chat proggies that will be received by the offending user telling them to quit or die....... I'll see if it works and get back to you all.
Pooh.....![]()
I use a custom version of snort that does not include flexresp therefore it doesn't recognize the react keyword and fails out on the rule....... Also, this used to send a message to the browser rather than a windows messaging message, (which would be real nice), so it is designed to limit web access more than anything else - shame really... I coulda had a lot of fun with my (L)users......![]()




), since the client will assume it is dropped at the firewall and allow the alternative connection to take place.
. I'll see if it works and get back to you all.
Reply With Quote