Snort mailing list archives

Depth and multi content rule help.


From: "larosa, vjay" <larosa_vjay () emc com>
Date: Tue, 17 Jun 2003 14:19:59 -0400

Hello,
 
If I have a rule with three pattern matches in it and I want to limit the
search depth for just one of the content searches, but I want the other two
pattern matches to search the whole packet is this possible?
This is an example of what I am trying to do.
 
alert any any -> any any (msg:"Test" content:"123"; content:"101112";
depth:48; content:"|ff 53 4d 42 a2|";)
 
Will this work? Or will my depth keyword apply to the all three content
matches?
 
Thanks!
 
vjl 
 
V.Jay LaRosa                   EMC Corporation
Information Security          4400 Computer Dr.
(508)898-7433 Office       Westboro, MA 01580
(508)353-1348 Cell           www.emc.com <http://www.emc.com> 
888-799-9750 Pager         vjl () emc com
 

Current thread: