|
Catch Suspicious Extensions [January 11, 2009]
|
|
Jan. 15, 2009, 11:21 AM
Post: #15
|
|||
|
|||
|
The filter for taking extensions is done:
Code: [HTTP headers]I think your above filters could be resumed to the following matching code working together with the taking extension filter Code: $TST(extension=(hta|e(ml|xe)|hlp|jse|lnk|url|ba(s|t)|c(om|md)|vb(e|s|)|s(cr|hs)|p(if|cd)|a(d(e| p)|nr)|c(hm|pl|rt)|i(ns|sp)|m(d(b|e)|s(c|i|p|t))|ws(f|h|c)))$LOG(R$DTM(c): Suspicious extension in \h\p)$CONFIRM(SUSPICIOUS FILE EXTENSION FOUND\n\nBlock connection to the URL below?\n\n\u\n) |
|||
|
« Next Oldest | Next Newest »
|

Search
Member List
Calendar
Help





![[-]](images/ONi/collapse.gif)