Redirect user that tries to view malicious URL or one that is not on the snort rule list? -


i have simple inline ips set using snort detection system. wondering if possible snort redirect user tries view url on disallowed list.

i'm subscribed snort live-updated/most recent database , working , giving me alerts, thing have seen far on topic of redirections go:

malicious attack -> snort recognizes attack -> redirected honeypot, , not:

user on lan -> snort recognized disallowed site -> redirects xyz page

you can use snort's replace keyword in rule replace disallowed url url of choosing. qualifications when using keyword new text must same length previous text.

you can use react keyword respond html page of choice, block connection too.


Comments

Popular posts from this blog

javascript - Jquery show_hide, what to add in order to make the page scroll to the bottom of the hidden field once button is clicked -

javascript - Highcharts multi-color line -

javascript - Enter key does not work in search box -