Snort mailing list archives

Re: How to use CIDR masks


From: Jack Pepper <pepperjack () afferentsecurity com>
Date: Tue, 12 Aug 2008 08:09:26 -0500

Quoting Salvo Danilo Giuffrida <salvodanilogiuffrida () gmail com>:

Hello, if in a Snort rule I write an address like this:
192.168.0.1/24

Is it the same as
192.168.0.0/24

or is it regarded as a single IP address?
Thanks

The one with the last octet zeroed out ( 192.168.0.0/24 ) is  
syntactically correct.  the other one is incorrect and should not be  
used.  Depending on the exact version of snort you are using, the  
incorrect syntax may or may not work as intended.


jp




-- 

Framework?  I don't need no stinking framework!

----------------------------------------------------------------
@fferent Security Labs:  Isolate/Insulate/Innovate  
http://www.afferentsecurity.com


-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: