Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » network contents scanning using snort

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

network contents scanning using snort


Posted by AliNaqvi on April 19, 2005 21:09:07

Hi,
Is it possible to scan through the contents of network using snort. I've tried it only got success in matching the header fields of the packet. For example if to scan through the web contents then i can only match the HTTP headers or some simple stuff which is present in the header.
My question is can snort be used to match the web contents. e.g. make a search on google and use snort to match some string instance within the result page returned by google etc. (i've tried to generate alert but no alert is generated at all. Even though the string is present inside the traffic)

Any help, comments or suggestion is appreciated.

TIA.

Regards,
Ali Naqvi