On Wed, Mar 17, 2004 at 08:32:32AM -0800, Mike Singleton wrote:
> Anyone know if is possible to filter out spyware with FW-NG? Is so, any
> white paper you could point me to would be appreciated.

Certain types of spyware can be caught using the "Worm-catcher" functionality.
Specifically the type of spyware that reports back to its owner via HTTP.

By spending a couple of minutes analysing what URL the spyware agent sends
it reports to, you can create a Worm Catcher url filter matching that request
and thereby effectively stopping (and detecting) the presens of that particular
type of spyware on your network.

Good luck,

/Kenny
--
Kenny Jansson                               [EMAIL PROTECTED]
Sentor AB, Orphei Dr�ngars plats 1,753 11 Uppsala, Sweden
phn: +46 (0) 18 65 30 00     |     gsm: +46 (0) 70 757 30 01

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to