Snort mailing list archives
Re: content options in Snort rule
From: Chris Green <cmg () sourcefire com>
Date: Tue, 21 Jan 2003 13:34:44 -0500
"Sonia K. Tsui" <sonia () ucsee eecs berkeley edu> writes:
Hi, As far as I understand, when Snort sees the content option, it will scan for signature against both header content and body content of http packet. Is there a way to tell whether the content signature is for header content or body content?
No, the only content that is "special" right now is uricontent when does the portion up to the HTTP version -- Chris Green <cmg () sourcefire com> I've had a perfectly wonderful evening. But this wasn't it. -- Groucho Marx ------------------------------------------------------- This SF.net email is sponsored by: Scholarships for Techies! Can't afford IT training? All 2003 ictp students receive scholarships. Get hands-on training in Microsoft, Cisco, Sun, Linux/UNIX, and more. www.ictp.com/training/sourceforge.asp _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- content options in Snort rule Sonia K. Tsui (Jan 21)
- Re: content options in Snort rule Chris Green (Jan 21)