Snort mailing list archives

Re: Could someone test a rule for me please?


From: Charlie Egan <chas5873 () gmail com>
Date: Mon, 7 Jul 2014 11:43:27 +0100

Sorry to be a pain guys, could somebody get back to me regarding my last
query?

Cheers,

Charlie


On Thu, Jul 3, 2014 at 11:39 AM, Charlie Egan <chas5873 () gmail com> wrote:

No worries Nathan!

Joel, I'm curious to what the |13| means in the content section? I can't
figure it out when looking at the stream content image I uploaded above
from Wireshark.

Your rule looks a lot better than mine, with the extra depth which I've
just read up about, so thanks for that.

Out of curiousity though, would my initial rule have worked without giving
out any false positives?

Cheers


On Wed, Jul 2, 2014 at 7:17 PM, lists () packetmail net <lists () packetmail net
wrote:

On 07/02/2014 12:56 PM, Joel Esler (jesler) wrote:
I think Nathan may have missed the “BitTorrent protocol” part.

Without a doubt, I completely missed it.  I profusely apologize Charlie.



------------------------------------------------------------------------------
Open source business process management suite built on Java and Eclipse
Turn processes into business applications with Bonita BPM Community Edition
Quickly connect people, data, and systems into organized workflows
Winner of BOSSIE, CODIE, OW2 and Gartner awards
http://p.sf.net/sfu/Bonitasoft
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: