|
|||||||||||
|
[Snort-sigs] Re: [Snort-devel] rules problem relating to offset?
From: Brian <bmc(at)snort.org>
Date: Mon Mar 31 2003 - 17:28:35 EST
On Mon, Mar 31, 2003 at 03:12:02PM -0600, Kreimendahl, Chad J wrote:
When you upgrade snort, you should upgrade your ruleset. This was corrected before 2.0.0 rc1 went out. alert tcp $EXTERNAL_NET any -> $HOME_NET 143 (msg:"IMAP list overflow attempt"; flow:established,to_server; content:" LIST |22 22| {"; nocase; byte_test:5,>,256,0,string,dec,relative; reference:nessus,10374; reference:cve,CAN-2000-0284; classtype:misc-attack; sid:1845; rev:7;) -brian This SF.net email is sponsored by: ValueWeb: Dedicated Hosting for just $79/mo with 500 GB of bandwidth! No other company gives more support or power for your dedicated server http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Mon Mar 31 18:04:13 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:26 EDT |
||||||||||
|
|||||||||||