Snort mailing list archives
Re: How to use CIDR masks
From: Jack Pepper <pepperjack () afferentsecurity com>
Date: Tue, 12 Aug 2008 08:09:26 -0500
Quoting Salvo Danilo Giuffrida <salvodanilogiuffrida () gmail com>:
Hello, if in a Snort rule I write an address like this: 192.168.0.1/24 Is it the same as 192.168.0.0/24 or is it regarded as a single IP address? Thanks
The one with the last octet zeroed out ( 192.168.0.0/24 ) is syntactically correct. the other one is incorrect and should not be used. Depending on the exact version of snort you are using, the incorrect syntax may or may not work as intended. jp -- Framework? I don't need no stinking framework! ---------------------------------------------------------------- @fferent Security Labs: Isolate/Insulate/Innovate http://www.afferentsecurity.com ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How to use CIDR masks Salvo Danilo Giuffrida (Aug 11)
- Re: How to use CIDR masks Jack Pepper (Aug 12)