Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Snort-devel] Simple Question!!

From: SAM IDS <sam_ids(at)yahoo.com>
Date: Mon Mar 29 2004 - 23:28:31 EST


hello ,
In the
Signature : alert ip $EXTERNAL_NET any -> $HOME_NET any (msg:"DOS IGMP dos attack"; content:"|02 00|"; depth: 2; ip_proto: 2; fragbits: M+; reference:cve,CVE-1999-0918; classtype:attempted-dos; sid:272; rev:2;)  

Whats meant by:
1.depth: 2
2.fragbits: M+  

thanks  

SAM



Do you Yahoo!?
Yahoo! Finance Tax Center - File online. File on time.

This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click

Snort-devel mailing list
Snort-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-devel Received on Mon Apr 5 10:48:43 2004

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:10 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library