Snort mailing list archives
Re: Snort rule for a pattern match?
From: "lists () packetmail net" <lists () packetmail net>
Date: Wed, 27 Mar 2013 09:55:51 -0500
On 03/27/2013 09:45 AM, Shields, Joseph (NIH/NIEHS) [C] wrote:
How can I write this rule?
Write the PCRE and I'll write the rule. You have to use byte_test/byte_extract or PCRE. Either way, IHMO, Snort isn't the best place to do this level of complex packet analysis because it'll be a costly rule. ------------------------------------------------------------------------------ Own the Future-Intel® Level Up Game Demo Contest 2013 Rise to greatness in Intel's independent game demo contest. Compete for recognition, cash, and the chance to get your game on Steam. $5K grand prize plus 10 genre and skill prizes. Submit your demo by 6/6/13. http://p.sf.net/sfu/intel_levelupd2d _______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- FW: Snort rule for a pattern match?, (continued)
- FW: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 07)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 26)
- Re: Snort rule for a pattern match? Joel Esler (Mar 26)
- Re: Snort rule for a pattern match? Jamie Riden (Mar 26)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 26)
- Re: Snort rule for a pattern match? Lay, James (Mar 26)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 26)
- Re: Snort rule for a pattern match? Lay, James (Mar 27)
- Re: Snort rule for a pattern match? lists () packetmail net (Mar 27)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 27)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 27)
- Re: Snort rule for a pattern match? lists () packetmail net (Mar 27)
- Re: Snort rule for a pattern match? Joel Esler (Mar 27)
- Re: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 26)
- FW: Snort rule for a pattern match? Shields, Joseph (NIH/NIEHS) [C] (Mar 07)