Snort mailing list archives

Re: Problem with Content rule option


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Thu, 18 Dec 2014 05:44:35 +0000

Perhaps a sample packet capture, rule, and snort.conf?

--
Joel Esler
Sent from my iPhone

On Dec 17, 2014, at 11:04 PM, Mark Greenman <mark.greenman.014 () gmail com<mailto:mark.greenman.014 () gmail com>> 
wrote:

Hi. I am new to snort. I want to use content rule option to execute some actions based on the content of the http 
response message (the payload). But, it can not work properly. For example, if I want to replace some word with 
another, the detection engine can detect some words in the http response message but can not some of the same words in 
the same message. Sometimes it can't even detect a single word. The problem is that it works properly for the content 
of the http header. Does anyone know the reason?

Thanks
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: