Snort mailing list archives

Test question


From: Phil Wood <cpw () lanl gov>
Date: Sun, 16 Dec 2001 19:12:01 -0700


Here is a rule from attack-responses.rules int the 1.8.3 release:

alert tcp any any -> any any (msg:"ATTACK RESPONSES id check returned root"; flags:A+; content: "uid=0(root)"; 
classtype:bad-unknown; sid:498; rev:2;)

I'd like to compliment the person who developed this rule.

Secondly, I'd like to propose a question to tickle your fancy.

If the second any were 22, and the first any was on your network, what 
would the classtype be?  Extra credit.  Fill in the blanks.

  systems are being compromised via the ___-__ ___________ ______ ________
  _____________ 

Later,

Phil


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: