Martin Roesch <roesch@sourcefire.com> writes:
> Look in the templates directory in the Snort source repository.
>
Don't do that unless it's been updated recently. Those templates have
been out of date for quite a while.
If you want to add a keyword, look at detection-plugins/*.c. If you
want to add something that looks at all traffic, look at the
preprocessors/*.c -- spp_rpc_decode.c is one of the simpler ones.
--
Chris Green
Chicken's thinkin'
-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-devel mailing list
Snort-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-devel
Received on Fri Feb 13 09:47:05 2004
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:08:12 EDT
|