Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Default Configuration from snort.conf Up: DCE/RPC Previous: Summary   Contents

Configuration Examples

Do not reassemble SMB fragmentation.

preprocessor dcerpc: \
        autodetect \
        disable_smb_frag \
        max_frag_size 4000

Specify specific ports, no autodetect. Do not reassemble SMB fragmentation.

preprocessor dcerpc: \
        ports smb { 139 445 } dcerpc { 135 } \
        disable_dcerpc_frag \
        memcap 50000



Steven Sturges 2006-12-08