|
|||||||||||
|
[Snort-sigs] Rule for Sebek2 Traffic
From: Andrew Hintz \(Drew\) <drew(at)overt.org>
Date: Thu Apr 10 2003 - 20:35:10 EDT
### Sebek2 Detection Rule ###
# you can set this to 'any' and still get a low # of false positives
# TTL is configurable, but 1 by default
# you'll get an alert on *every* sebek packet. If you only want to
alert udp any $SEBEK_PORTS -> any $SEBEK_PORTS (msg:"Sebek2 traffic"; \
ttl:1; \
#EOF
-- ^Drew http://guh.nu --Begin PGP Fingerprint-- 3C6C F712 0A52 BD33 C518 5798 9014 CA99 2DA0 5E78 --End PGP Fingerprint-- ------------------------------------------------------- This SF.net email is sponsored by: Etnus, makers of TotalView, The debugger for complex code. Debugging C/C++ programs can leave you feeling lost and disoriented. TotalView can help you find your way. Available on major UNIX and Linux platforms. Try it free. www.etnus.com _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigsReceived on Thu Apr 10 21:04:58 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:26 EDT |
||||||||||
|
|||||||||||