Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Development » Snort rules to detect brute force attack a web site

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Snort rules to detect brute force attack a web site


Posted by cobra on August 03, 2005 03:39:00

Hi all,

I was just thinking weather we can have snort rule to detect brute force attack (similar attacks....).

Mmm like authentication failed messages in a threshold time so that we can detect an attack even if it passes security appliance.