Snort mailing list archives

Creating a new rule


From: David Cintron <david () dcvast com>
Date: Wed, 16 Apr 2003 14:28:21 -0500 (CDT)


I'm having problems picking up an alert from a rule i created. Here is the
rule.

alert tcp any any -> IP ADDRESS/32 80 (uricontent:"\>\"";
msg:"Vignette Attack";)

Here is what i am using to see if snort will pick it up.


telnet IP ADDRESS 80 <Return>
GET /foo/bar?x=""""">>>> HTTP/1.0 <Return>
<Return>

Any Help would be great.



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: