[Snort-sigs] creating new sigs [newbie]

Chris Hare, CISSP, CISA chare at ...1435...
Sat Apr 5 05:33:14 EST 2003

I am a newbie to snort.

I want to create a rule to catch CodeRed default.ida attacks.  I have what I think is the right signature defined, but I need more information on the SID.  How do I select an SID?  is it purely random to test with or what?


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20030405/8e2f4bd5/attachment.html>

More information about the Snort-sigs mailing list