Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » 1417 help!!

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

1417 help!!


Posted by rajat on April 08, 2005 01:55:58

i modifeied the rule for 1417 as
alert udp any any -> $HOME_NET 161 (msg:"SNMP request udp"; content:!"mystring"; reference:bugtraq,4088; reference:bugtraq,4089; reference:bugtraq,4132; reference:cve,2002-0012; reference:cve,2002-0013; classtype:attempted-recon; sid:78541417; rev:9;)
here my string is community string.he problem comming is snort dsn't generate the alert for any oter community string.can anyone please let me know way could be wron with my configuration.