Snort mailing list archives

FTP rules, different port


From: Michael B <miboe60 () hotmail com>
Date: Sun, 26 Apr 2015 15:00:29 +0200

Hello,
I have enabled the 'protocol-ftp' rules in PulledPork, however several FTP attacks are not reported. I went to check 
for the rules, and they almost all have port '21' hardcoded as a port, instead of the more general '$FTP_PORTS' 
variable..
My FTP server is running on another port, and is thus not protected by most of the 21 rules.. Do I have to copy paste 
them in my custom ruleset, or is there something that I'm missing?

 
                                          
------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: