Snort mailing list archives
smtp rule help
From: "ricardo () datawan net" <ricardo () datawan net>
Date: Mon, 18 Nov 2002 16:02:57 -0500
I have been running snort for a while with Demarc as a front-end. I have never needed to write my own rules but thought it was time to learn! Client has a network that has Mail Relay open for all local users. I want to log all outgoing email that is NOT from a specific domain. "user () somedomain com". I tried the following and it seems to work but just want to confirm this is right! Or the best way to do it. alert tcp $HOME_NET any -> $EXTERNAL_NET 25 (msg:"SMTP Rule- My custom SMTP Rule"; content:!"@somedomain.com"; depth: 22; flags: A+; nocase; classtype:misc-activity;) thanks in advance! Ricardo LondoƱo -------------------------------------------------------------------- mail2web - Check your email from the web at http://mail2web.com/ . ------------------------------------------------------- This sf.net email is sponsored by: To learn the basics of securing your web site with SSL, click here to get a FREE TRIAL of a Thawte Server Certificate: http://www.gothawte.com/rd524.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- smtp rule help ricardo () datawan net (Nov 18)