Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
I've got no idea as to separate contentfilters, but you should be able to block Kazaa and Audiogalaxy because they use std ports.
Iptables has some form of contentfiltering called stringmatching support (IIRC) but that's experimental. Astaro and Suse promote fw packages having "content filtering", but by that they only mean HTTP traffic (using Squid prolly).
Another way I could think of would be to find some form of signature in that traffic, but that'll be hard, because Kazaa doesn't only do mp3, and let Snort block it.
Maybe you should review your fw rules, and only accept traffic for what you would explicitly allow.
my firewall is set up in the way, that only explicitly allowed ports are open. nonetheless, sw like icq is able to communicate via (e.g.) port 80. that makes it impossible for me, to disallow icq ...
binary patterns or signatures are interresting, but that's what i actually wanted to ask ... does someone konw something to filter via this criterias ?
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.