|
|||||||||||
|
Re: [Snort-sigs] Not sure I understand "RPC AMD TCP pid request"..
From: Brian <bmc(at)snort.org>
Date: Sun May 04 2003 - 13:00:51 EDT
On Fri, May 02, 2003 at 03:55:54PM -0700, Tom Arseneault wrote:
> What I don't understand is why the destination port is 500(tcp), everything
The port is NOT 500, the port is "any port from 500 and up." amd has its own service (300019) that generally runs on ports above 500. Port 111 is for portmap. In this rule, we are looking for the pid request on the amd service, NOT the portmap request for where this service is running. > I did a quick web search and was unable to find any indications that this
Well, its very easy.
-brian This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Sun May 4 13:49:27 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:27 EDT |
||||||||||
|
|||||||||||