Snort mailing list archives
Creating a new rule
From: David Cintron <david () dcvast com>
Date: Wed, 16 Apr 2003 14:28:21 -0500 (CDT)
I'm having problems picking up an alert from a rule i created. Here is the rule. alert tcp any any -> IP ADDRESS/32 80 (uricontent:"\>\""; msg:"Vignette Attack";) Here is what i am using to see if snort will pick it up. telnet IP ADDRESS 80 <Return> GET /foo/bar?x=""""">>>> HTTP/1.0 <Return> <Return> Any Help would be great. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Creating a new rule David Cintron (Apr 17)