Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » General Chat » figuring out these rules

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

figuring out these rules


Posted by joma on March 09, 2006 10:29:28

1. Create an alert from any incoming packets from source address 66.35.250.203, source port 80 to any machine on the internal network.

2. Create an alert for any incoming packet whose contents contain "tcpdump" (case sensitive).

3. Create an alert for any outgoing packets that list the CUPS protocol

Posted by sf_web on March 10, 2006 06:06:09

Hi,

This thread is listed at:
http://www.snort.org/reg-bin/forums.cgi?forum_id=1&topic_id=2198
http://www.snort.org/reg-bin/forums.cgi?forum_id=2&topic_id=2196
http://www.snort.org/reg-bin/forums.cgi?forum_id=101&topic_id=2200

In the future, please post to only 1 forum so that discussion can be consolidated to one thread, closing out this thread...

Richard Bewley
Snort Web Team