Snort mailing list archives
URI content not being identified
From: Jelte <masterjel5000 () hotmail com>
Date: Thu, 8 May 2014 17:44:34 +0200
Hello all, I have the following Snort rule: alert tcp any any -> $HOME_NET $HTTP_PORTS (msg: "HTTP content test"; content: "test.php"; classtype:web-application-attack; sid:5000001; rev:1;) Now when I visit mysite.com/test.php an alert is correctly generated. However, as soon as I change "content" to "uricontent", or add "http_uri;" before the "classtype", no alert is generated. I analyzed the traffic using tshark and I can see requests to "test.php" coming through. Do you know any step I could take that may help to identify what is causing this? Thanks! ------------------------------------------------------------------------------ Is your legacy SCM system holding you back? Join Perforce May 7 to find out: • 3 signs your SCM is hindering your productivity • Requirements for releasing software faster • Expert tips and advice for migrating your SCM now http://p.sf.net/sfu/perforce _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- URI content not being identified Jelte (May 08)
- Re: URI content not being identified Y M (May 08)
- Re: URI content not being identified Jelte (May 08)
- Re: URI content not being identified Y M (May 08)
- Re: URI content not being identified Jelte (May 09)
- Message not available
- Re: URI content not being identified Jelte (May 09)
- Message not available
- Message not available
- Re: URI content not being identified Jelte (May 09)
- Re: URI content not being identified Joel Esler (jesler) (May 12)
- Re: URI content not being identified Jelte (May 12)
- Re: URI content not being identified Jelte (May 08)
- Re: URI content not being identified Y M (May 08)