Snort mailing list archives
Depth and multi content rule help.
From: "larosa, vjay" <larosa_vjay () emc com>
Date: Tue, 17 Jun 2003 14:19:59 -0400
Hello, If I have a rule with three pattern matches in it and I want to limit the search depth for just one of the content searches, but I want the other two pattern matches to search the whole packet is this possible? This is an example of what I am trying to do. alert any any -> any any (msg:"Test" content:"123"; content:"101112"; depth:48; content:"|ff 53 4d 42 a2|";) Will this work? Or will my depth keyword apply to the all three content matches? Thanks! vjl V.Jay LaRosa EMC Corporation Information Security 4400 Computer Dr. (508)898-7433 Office Westboro, MA 01580 (508)353-1348 Cell www.emc.com <http://www.emc.com> 888-799-9750 Pager vjl () emc com
Current thread:
- Depth and multi content rule help. larosa, vjay (Jun 17)
- Re: [Snort-sigs] Depth and multi content rule help. Chris Green (Jun 18)