|
|||||||||||
|
Re: [Snort-sigs] general sig question
From: Tom Arseneault <TArseneault(at)counterpane.com>
Date: Tue May 27 2003 - 18:45:35 EDT
Brian, Am I reading the manual wrong? This seems to be exactly what he's asking for (tagging is anyway)?
2.3.31 Tag
Format tag: <type>, <count>, <metric>, [direction] type
session
packets
alert tcp !$HOME_NET any -> $HOME_NET 143 (flags: A+; \
content: "|e8 c0ff ffff|/bin/sh"; tag: host, 300, packets, src; \
msg: "IMAP Buffer overflow, tagging!";)
alert tcp !$HOME_NET any -> $HOME_NET 23 (flags: S; \
tag: session, 10, seconds; msg: "incoming telnet session";)
Figure 2.26: Tag Keyword Examples
On Thu, May 22, 2003 at 02:03:17AM -0400, d_greenjr wrote:
You can't do that in snort right now as we do not have thresholding support. -brian
Tom Arseneault
This SF.net email is sponsored by: ObjectStore. If flattening out C++ or Java code to make your application fit in a relational database is painful, don't do it! Check out ObjectStore. Now part of Progress Software. http://www.objectstore.net/sourceforge Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Tue May 27 19:26:07 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:29 EDT |
||||||||||
|
|||||||||||