While syslogging IDS data and using HTTP proxy, I've noticed a lot of these messages:
Apr 30 17:45:45 10.6.1.254 2004:04:30-17:43:36 snort[17543]: [1:1432:0] D P2P GNUTella GET [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {PROTO006} 10.6.1.1:15817 -> 10.6.1.254:8080
Apr 30 17:45:48 10.6.1.254 2004:04:30-17:43:39 snort[17543]: [1:1432:0] D P2P GNUTella GET [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {PROTO006} 10.6.1.1:15817 -> 10.6.1.254:8080
Apr 30 17:45:55 10.6.1.254 2004:04:30-17:43:45 snort[17543]: [1:1432:0] D P2P GNUTella GET [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {PROTO006} 10.6.1.1:15817 -> 10.6.1.254:8080
Apr 30 17:46:07 10.6.1.254 2004:04:30-17:43:57 snort[17543]: [1:1432:0] D P2P GNUTella GET [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {PROTO006} 10.6.1.1:15817 -> 10.6.1.254:8080
Apr 30 17:46:31 10.6.1.254 2004:04:30-17:44:21 snort[17543]: [1:1432:0] D P2P GNUTella GET [Classification: Potential Corporate Privacy Violation] [Priority: 1]: {PROTO006} 10.6.1.1:15817 -> 10.6.1.254:8080
So I go turn on blocking for that rule and all of the sudden (Suprise, Suprise) the http proxy stops working.
This thread was automatically locked due to age.