Why do Sophos have so litel signiture? On pfsense with snort, i have 5 times more, with all optios (Oracle, user agent, netbios,apache, ntp, ftp, smtp,..., .).
just mark "Add extra warnings" as described on top of the window [;)]
[HTML]Add extra warnings: When this option is activated, the group will also include rules which are used for warning-purposes only. These rules may potentially cause false alarms, so they are not included by default.[/HTML]
I've just answered simbys question [;)] Why do you think that these setting not set all rules to drop? I'm absolutly at your site if you say that this is not wise.
* 1:28496 ENABLED BROWSER-IE Microsoft Internet Explorer createRange user after free attempt (browser-ie.rules) * 1:28893 DISABLED BROWSER-OTHER known revoked certificate for Tresor CA (browser-other.rules) * 1:20843 ENABLED FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (file-other.rules)