Snort mailing list archives

snort 2.3.3 --enable-flexresp


From: hans <rosa.schwein () ma yer at>
Date: Mon, 25 Apr 2005 10:36:28 +0200


hi all 

i tried the experimental feature '--enable-flexresp' for 
compiling snort 2.3.3 on solaris 9 ( both sparc and intel plattform ) 

the first tests did run well, the following rule did 
disconnect an incomming connection immediate:

alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; resp:rst_all; )

the next step was to modify this rule sligthly. the disconnect should 
only appear, if the word "hello" was seen, with this rule: 

alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; content:"hello"; resp:rst_all; )

i telnet to port 25, key in "hello"  ( knowing it's not a smtp-dialog  ) 
and nothing happens. i get a logentry, so the rule is involved 
if the word "hello" is seen, but no disconnect. 

i searched a lot of time around the internet, but could find 
any advice, what the problem could be. 

every advice would be helpfully. 

just disconnecting any incomming connection could be the idea, a 
tcpwrapper could this job too. 


best regards 
hans 

-- 



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: