Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: distance Up: offset Previous: offset   Contents

Format

offset: <number>;

Figure: Combined Content, Offset and Depth Rule. Skip the first 4 bytes, and look for cgi-bin/phf in the next 20 bytes
\begin{figure}\begin{verbatim}alert tcp any any -> any 80 (content: ''cgi-bin/phf''; offset:4; depth:20;)\end{verbatim}
\par\end{figure}



Steven Sturges 2006-12-08