Snort mailing list archives

Tracing certain file requests ...


From: "Jon Baer" <security () jonbaer net>
Date: Mon, 12 May 2003 09:49:29 -0700

Could some help me here ... im trying to keep tabs on specific binary files
through Snort and would like to log when the cross the network, to write a
rule for this Im attempting to hexdump the contents of the file out but how
would the rule be setup?  Does this stuff work effectively if say I only
took the 1st 100 bytes of all traffic?

Thanks in advance.

- Jon



-------------------------------------------------------
Enterprise Linux Forum Conference & Expo, June 4-6, 2003, Santa Clara
The only event dedicated to issues related to Linux enterprise solutions
www.enterpriselinuxforum.com

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: