Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 23

Thread: New Feature

  1. #11
    mdh
    mdh is offline
    Untangle Ninja mdh's Avatar
    Join Date
    Aug 2007
    Posts
    4,802

    Default

    Yes, but he might refer it to someone else who works with business development (relationships between Untangle and others). Dirk is the right person to either handle it or get it handled.
    This space reserved for profound thought.....which does happen on occasion."

  2. #12
    Untanglit
    Join Date
    Nov 2008
    Posts
    16

    Default

    Another great feature that would be absolutely easy to implement, and would please a lot of people : make the SMTP port that is being used configurable. Right now, the SPAM blocker, the PHISH blocker and the virus blocker have the ability to check SMTP traffic, but only SMTP traffic on port 25. Many people have their SMTP come in on another port (security or ISP that blocks port 25). This SMTP traffic on alternate ports passes al the mentioned modules unchecked. Why not make a small configuration page in the network section where you can indicate the alternate SMTP port ?

  3. #13
    Untangle Ninja juank's Avatar
    Join Date
    Aug 2007
    Location
    Athens
    Posts
    1,474

    Default

    Quote Originally Posted by greyman View Post
    From skimming through the information provided on their site it looks like it uses an augmented snort engine. This coupled with the resources mentioned for system requirements gives (1 GB RAM) gives me the feeling it might not be real light.

    Here is a commercial version of the same type of application http://www.damballa.com

    But I do like the idea of consideration for it to be added to UT .
    So is a kind-of-snort engine or just extra VERY GOOD snort rules? if the later, it will be really easy to include in Untangle.
    --------------------------------
    Juan Machado
    --------------------------------

  4. #14
    Untangle Ninja hescominsoon's Avatar
    Join Date
    Sep 2007
    Posts
    1,585

    Default

    A lighter engine isn't going to be as thorough in this case. The 1gb is more for the java than the snort.

  5. #15
    Master Untangler
    Join Date
    May 2008
    Posts
    104

    Default

    This does look interesting...

    I remember reading about similar groups writing extended snort rules for catching botnets and other malware phoning home.

  6. #16
    Untangle Ninja juank's Avatar
    Join Date
    Aug 2007
    Location
    Athens
    Posts
    1,474

    Default

    Yes, for example (of course this one doesn't have to be related to a BOT):

    alert udp any any -> any 69 (msg:"TFTP GET nc.exe"; content: "|0001|"; offset:0; depth:2; content:"nc.exe"; offset:2; nocase; classtype:successful-admin; sid:1441; rev:2

    but ... you don't really want any person or device trying to download NC.exe, if you know what I mean...

    If interested, you can read more at http://www.giac.org/certified_profes.../gsec/4095.php
    --------------------------------
    Juan Machado
    --------------------------------

  7. #17
    Untangle Ninja juank's Avatar
    Join Date
    Aug 2007
    Location
    Athens
    Posts
    1,474

    Default

    What about this ?
    http://www.bleedingsnort.com/bleeding-all.rules
    http://www.bleedingthreats.net/rules/

    This sounds like a good idea .. what do you guys think ?
    --------------------------------
    Juan Machado
    --------------------------------

  8. #18
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,691

    Default

    have them email me dmorris@untangle.com

    the license is not open source so we can't include it without their permission.

    if its just a set of snort rules i'm not sure it would fit so well inside IPS, unless the rules just use application layer matchers.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  9. #19
    Master Untangler jontz's Avatar
    Join Date
    Sep 2008
    Posts
    107

    Default

    www.bleedingthreats.net ...sounds like the sort of site I usually have to add to the web filter

  10. #20
    Untangle Ninja juank's Avatar
    Join Date
    Aug 2007
    Location
    Athens
    Posts
    1,474

    Default

    Quote Originally Posted by jontz View Post
    www.bleedingthreats.net ...sounds like the sort of site I usually have to add to the web filter
    It may sounds like but ... it is not..
    --------------------------------
    Juan Machado
    --------------------------------

Page 2 of 3 FirstFirst 123 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2