Snort mailing list archives

no alerts on the dos screen


From: mary andrews <maryandrews22 () gmail com>
Date: Tue, 17 Nov 2009 14:04:07 -0500

# testing.rules
alert icmp any any -> any any (msg:"$$$$$TESTING rule$$$$$"; sid:1000001;)
alert tcp any any -> any any (msg:"test ebay rule";
flow:to_server,established; content:"ebay.com"; nocase; sid:10000002;
rev:1;)
--------

See, if we ping any  host, we get the $$$$$TESTING rule$$$$$  message on the
dos screen.

But if we visit www.ebay.com from our browser, we dont get to see any alerts
on the dos screen.


please, very please?

thanks,
m
------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: