All of lore.kernel.org
 help / color / mirror / Atom feed
From: rruegner <robowarp@gmx.de>
To: Red Hat <lilo123456@hotmail.com>
Cc: netfilter@lists.netfilter.org
Subject: Re: What to do to protet our send from the attacks which is caused by	worms?
Date: Fri, 17 Sep 2004 22:55:35 +0200	[thread overview]
Message-ID: <414B4F47.20805@gmx.de> (raw)
In-Reply-To: <BAY12-F11jlA733LJa500009c09@hotmail.com>

Hi, you can use dansguardian with antivirus plugin for http, and amavis 
new for smtp, and frox for ftp, use clamd as free antivirus scanner
so you have a complete antivirus solution,
alternative for http use apache in proxy mode with mod_vir ( dont know 
exactly how the name was ) coupled wtih squid and squidguard.
Do a conservative firewall for the the rest of the ports with iptables.
You can use some comercial linux distros like astaro or gibraltar with 
all packed  in , or ipcop with serveral plugins.
After all you need a daily update of win machines and comercial antivir 
on it like antivir , and a susserver in your lokal network for security 
updates, check your users not to act as lokal or domain admins
and advice them not to use outlook (express) or internet explorer,
install thunderbird and firefox and set them as default in windows,
install spybot on all machines.
Snort on the firewall will help you find out what attacks are going on
So you have a working pack which gives you relativ sercurity as long
your staying up to date , with all signatures of viri.
Set acls on your switches and check only mac adresses you know on them.
dont use buggy win xp firewall, check out ie. kerio firewall for windows.
Security is a concept ,not one software or os
Regards

Red Hat schrieb:
> Hi,
> 
> What to do to protet our send from the attacks which is caused by worms in
> Microsoft XP OS of our users? Our user may have worms in their system & it
> causes that our send go up & up that our send is going upper than which we
> have to use. for example if we can send 64Kb/s their worm cause our send go
> upper than this. These worms would cause our network work too bad. I mean
> the other user which doesn't have worm, can't work properly.
> Hope you understand our problem. Now I want to use a software or command in
> my Linux server which contain squid to protect our send not to go up 
> because
>  of the worm of our users.
> I think we can protect it by iptables but I don't know how should I do 
> this?
> So wanted to intall smoothwall to help me. Now I understand that it can't
> help me.
> what's you opinion & how should I do that?
> 
> Thanks in advance.
> 
> Best Regards,
> Mehdi
> 
> _________________________________________________________________
> Tired of spam? Get advanced junk mail protection with MSN 8. 
> http://join.msn.com/?page=features/junkmail
> 
> 


      parent reply	other threads:[~2004-09-17 20:55 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-09-17 19:10 What to do to protet our send from the attacks which is caused by worms? Red Hat
2004-09-17 19:20 ` Aleksandar Milivojevic
2004-09-17 20:55 ` rruegner [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=414B4F47.20805@gmx.de \
    --to=robowarp@gmx.de \
    --cc=lilo123456@hotmail.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.