Snort mailing list archives
Re: How to Craft a rule that negates multiple ports??
From: Michael Scheidell <scheidell () secnap net>
Date: Wed, 29 May 2002 11:14:01 -0400 (EDT)
This rule won't load: alert tcp $EXTERNAL_NET ![80,443] -> $HOME_NET 3372 (msg:"DOS MSDTC attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006; classtype:attempted-dos; sid:1408; rev:2;)May 28
what traffic, coming in from ports 81-442 would you miss?
alert tcp $EXTERNAL_NET !80:443 -> $HOME_NET 3372 (msg:"DOS MSDTC attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006; classtype:attempted-dos; sid:1408; rev:2;)
add in alert tcp $EXTERNAL_NET 81:442 -> $HOME_NET 3372 (msg:"DOS MSDTC attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006; classtype:attempted-dos; sid:1408; rev:2;) -- Michael Scheidell SECNAP Network Security, LLC (561) 368-9561 scheidell () secnap net http://www.secnap.net/ _______________________________________________________________ Don't miss the 2002 Sprint PCS Application Developer's Conference August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How to Craft a rule that negates multiple ports?? Alan_Kloster (May 29)
- Re: How to Craft a rule that negates multiple ports?? Michael Scheidell (May 29)