All of lore.kernel.org
 help / color / mirror / Atom feed
* Idea: string replace
@ 2002-10-01  1:13 Peter Surda
  2002-10-01  7:27 ` Patrick Schaaf
  0 siblings, 1 reply; 5+ messages in thread
From: Peter Surda @ 2002-10-01  1:13 UTC (permalink / raw)
  To: netfilter-devel

[-- Attachment #1: Type: text/plain, Size: 1222 bytes --]

Hello!

I have an idea, which is IMHO very suitable for China. Er, no, wanted to say
something different, suitable for me. How about adding a --replace-with option
to the string match? Is it difficult? Or could this be done with the NETLINK
target?

Why am I asking? I would like to prevent users behind a router becoming
infected with a virus (a specific one, not the thousands others). I made a
string match for it and direct all pop3/imap trafic through this rule. The
problem is, although I can find it, I can't reasonably get rid of it. The
most reasonable solution seems to be to -j REJECT --reject-with tcp-reset, but
I assume this causes problems.  So I'd rather change the string to something
bogus, which will make the virus unexecutable.

Or do you know a filtering transparent pop3/imap proxy? I have no access to
the dozens of servers the users have emails on. Unless the solution is fully
transparent, it will cause too high organisational overhead which is not
sensible to manage for us. Also not manageable is educating the users about
"safe use of computers".

Bye,

Peter Surda (Shurdeek) <shurdeek@panorama.sth.ac.at>, ICQ 10236103, +436505122023

--
                   Disc space - The final frontier.

[-- Attachment #2: Type: application/pgp-signature, Size: 232 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2002-10-02 13:44 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-01  1:13 Idea: string replace Peter Surda
2002-10-01  7:27 ` Patrick Schaaf
2002-10-01 21:06   ` Peter Surda
2002-10-01 23:33     ` Peter Surda
2002-10-02 13:44       ` Gianni Tedesco

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.