Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Snort-sigs] Not looking in Email

From: Dale L. Handy <dhandy(at)nitrodata.com>
Date: Wed May 21 2003 - 23:45:16 EDT

Actually, what you want is:

alert tcp any any <> !$SMTP_SERVERS 25 (msg:"ETCPASSWD"; flags:A+; content:"/etc/passwd"; sid:1000004;)

or:

alert tcp any any <> $HOME_NET !25 (msg:"ETCPASSWD"; flags:A+; content: "/etc/passwd"; sid:1000004;)

Of course, that won't stop it from looking in pop3 e-mail via port 110 or IMAP...

security people wrote:

>Use something like the following:

-- 
"The trouble with doing something right the first time 
 is that nobody appreciates how difficult it was."

-- Dale L. Handy, P.E.
   dale@srv.net          (208) 552-5332 (work)          (208) 403-6424 (cell)




-------------------------------------------------------
This SF.net email is sponsored by: ObjectStore.
If flattening out C++ or Java code to make your application fit in a
relational database is painful, don't do it! Check out ObjectStore.
Now part of Progress Software. 
http://www.objectstore.net/sourceforge
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
Received on Thu May 22 00:37:10 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:29 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library