|
|||||||||||
|
Re: [Snort-users] byte_test, byte_jump, distance, within
From: Chris Green <cmg(at)sourcefire.com>
Date: Mon Mar 31 2003 - 08:58:10 EST "Clemens, Dan" <Dan.Clemens@healthsouth.com> writes: > 1. (*) text/plain ( ) text/html
src/detection-plugins/sp_byte_{check,jump}.c has good comments at the top of the files. >From a reply to Phil wood earlier:
The easiest way to view distance is a.{4}.*b where that maps to: content: "a"; content: "b"; distance: 4; Within bounds the number of bytes that will be checked prior. -- Chris GreenReceived on Mon Mar 31 10:05:03 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 11:50:32 EDT |
||||||||||
|
|||||||||||