Snort mailing list archives
[Snort-user] dynamic variable for content match
From: zT <zzahra88 () gmail com>
Date: Mon, 26 Jan 2015 23:45:47 +0330
hello All, i am new in snort. i want to get a keyword from ubunt terminal and search it in packet( content match). do this with static value is something like this: alert tcp any any -> any any (msg:" your content found"; sid:100000; content:"something to find"; ) Any help is highly appreciated. Thanks and Regards, ------------------------------------------------------------------------------ Dive into the World of Parallel Programming. The Go Parallel Website, sponsored by Intel and developed in partnership with Slashdot Media, is your hub for all things parallel software development, from weekly thought leadership blogs to news, videos, case studies, tutorials and more. Take a look and join the conversation now. http://goparallel.sourceforge.net/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- [Snort-user] dynamic variable for content match zT (Jan 26)
- Re: [Snort-user] dynamic variable for content match Al Lewis (allewi) (Jan 26)
- Re: [Snort-user] dynamic variable for content match zT (Jan 26)
- Re: [Snort-user] dynamic variable for content match waldo kitty (Jan 27)
- Re: [Snort-user] dynamic variable for content match zT (Jan 27)
- Re: [Snort-user] dynamic variable for content match waldo kitty (Jan 28)
- Re: [Snort-user] dynamic variable for content match zT (Jan 28)
- Re: [Snort-user] dynamic variable for content match Al Lewis (allewi) (Jan 29)
- Re: [Snort-user] dynamic variable for content match zT (Jan 29)
- Re: [Snort-user] dynamic variable for content match zT (Jan 26)
- Re: [Snort-user] dynamic variable for content match Al Lewis (allewi) (Jan 26)