[Snort-sigs] more than one port in a rule?

Russell Fulton r.fulton at ...575...
Tue Apr 30 19:32:03 EDT 2002

	Since we use a lot of IMAP around here I would like to modify some of
the snort POP rules to also work with IMAP.  So far as I can tell from
rtfm I need to actually duplicate the rule with 143 instead of 110. 
What I would like to do is:
alert tcp any any -> any [110,143](...)

Have I got this right? or is there a way to specify a list rather than
just a range for ports.

Russell Fulton, Computer and Network Security Officer
The University of Auckland,  New Zealand

More information about the Snort-sigs mailing list