Snort mailing list archives

Re: How to Craft a rule that negates multiple ports??


From: Michael Scheidell <scheidell () secnap net>
Date: Wed, 29 May 2002 11:14:01 -0400 (EDT)


This rule won't load:

alert tcp $EXTERNAL_NET ![80,443] -> $HOME_NET 3372 (msg:"DOS MSDTC
attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006;
classtype:attempted-dos; sid:1408; rev:2;)May 28

what traffic, coming in from ports 81-442 would you miss?

alert tcp $EXTERNAL_NET !80:443 -> $HOME_NET 3372 (msg:"DOS MSDTC
attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006;
classtype:attempted-dos; sid:1408; rev:2;)

add in

 alert tcp $EXTERNAL_NET 81:442 -> $HOME_NET 3372 (msg:"DOS MSDTC
 attempt"; flags:A+; dsize:>1023; reference:bugtraq,4006;
 classtype:attempted-dos; sid:1408; rev:2;)

-- 
Michael Scheidell
SECNAP Network Security, LLC
(561) 368-9561 scheidell () secnap net
http://www.secnap.net/


_______________________________________________________________

Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: