Snort mailing list archives
Identify outbound SSH connections
From: Craig Merchant <cmerchant () responsys com>
Date: Wed, 9 Jan 2013 02:14:53 +0000
Is there a rule in the emerging threats or sourcefire rule base that will identify an SSH or SSL connection that goes from $HOME_NET -> !$HOME_NET, particularly on non-standard ports? Thx. Craig
------------------------------------------------------------------------------ Master Java SE, Java EE, Eclipse, Spring, Hibernate, JavaScript, jQuery and much more. Keep your Java skills current with LearnJavaNow - 200+ hours of step-by-step video tutorials by Java experts. SALE $49.99 this month only -- learn more at: http://p.sf.net/sfu/learnmore_122612
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Identify outbound SSH connections Craig Merchant (Jan 08)
- <Possible follow-ups>
- Re: Identify outbound SSH connections Y M (Jan 08)