Re: [W3af-develop] Snort rules to detect malware

2013-10-07 Thread Andres Riancho
esets? >>> >>> Regards, >>> >>>> On Sat, Oct 5, 2013 at 11:37 PM, Andri Herumurti >>>> wrote: >>>> Hi Andres, >>>> >>>> how if use Suricata than Snort ? >>>> here is the comparison : http://wiki.aan

Re: [W3af-develop] Snort rules to detect malware

2013-10-07 Thread Andri Herumurti
>>> wrote: >>> Hi Andres, >>> >>> how if use Suricata than Snort ? >>> here is the comparison : http://wiki.aanval.com/wiki/Snort_vs_Suricata >>> >>> Regards, >>> Andri >>> >>> >>> __

Re: [W3af-develop] Snort rules to detect malware

2013-10-06 Thread Andres Riancho
gt;> To: "w3af-us...@lists.sourceforge.net" ; >> "w3af-develop@lists.sourceforge.net" >> Sent: Sunday, October 6, 2013 3:38 AM >> Subject: [W3af-develop] Snort rules to detect malware >> >> Guys, >> >> We already have a clamav plugin t

Re: [W3af-develop] Snort rules to detect malware

2013-10-06 Thread Andres Riancho
eforge.net" ; > "w3af-develop@lists.sourceforge.net" > Sent: Sunday, October 6, 2013 3:38 AM > Subject: [W3af-develop] Snort rules to detect malware > > Guys, > > We already have a clamav plugin that will identify if an http > response body (usually a PE, DLL

Re: [W3af-develop] Snort rules to detect malware

2013-10-05 Thread Andri Herumurti
t: Sunday, October 6, 2013 3:38 AM Subject: [W3af-develop] Snort rules to detect malware Guys,     We already have a clamav plugin that will identify if an http response body (usually a PE, DLL, ELF, PDF, DOC etc.) contains a virus or not. The other day I was thinking about how to improve this

[W3af-develop] Snort rules to detect malware

2013-10-05 Thread Andres Riancho
Guys, We already have a clamav plugin that will identify if an http response body (usually a PE, DLL, ELF, PDF, DOC etc.) contains a virus or not. The other day I was thinking about how to improve this and came up with the idea of using snort rules to detect malware [0] The idea is rather