Snort mailing list archives
Test question
From: Phil Wood <cpw () lanl gov>
Date: Sun, 16 Dec 2001 19:12:01 -0700
Here is a rule from attack-responses.rules int the 1.8.3 release: alert tcp any any -> any any (msg:"ATTACK RESPONSES id check returned root"; flags:A+; content: "uid=0(root)"; classtype:bad-unknown; sid:498; rev:2;) I'd like to compliment the person who developed this rule. Secondly, I'd like to propose a question to tickle your fancy. If the second any were 22, and the first any was on your network, what would the classtype be? Extra credit. Fill in the blanks. systems are being compromised via the ___-__ ___________ ______ ________ _____________ Later, Phil _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Test question Phil Wood (Dec 16)
- Re: Test question Jose Celestino (Dec 16)
- Re: Test question Paul Cardon (Dec 16)
- Re: Test question Jose Celestino (Dec 16)
- Re: Test question Paul Cardon (Dec 16)
- Re: Test question Jose Celestino (Dec 16)
- Re: Test question Paul Cardon (Dec 16)
- Re: Test question Erik Fichtner (Dec 16)
- Re: Test question Jose Celestino (Dec 16)
- Re: Test question Greg Herlein (Dec 16)
- Re: Test question Jose Celestino (Dec 16)
- Re: Test question James (Dec 16)
- Re: Test question Ralf Hildebrandt (Dec 17)