[Snort-sigs] snort-rules STABLE update @ Mon Dec 1 13:15:17 2003

Frank Knobbe frank at ...1978...
Wed Dec 3 20:03:15 EST 2003


On Mon, 2003-12-01 at 12:15, bmc at ...95... wrote:
>      file -> backdoor.rules
>      alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"BACKDOOR typot trojan traffic"; flags:S,12; window:55808; sid:2182; rev:1;)

Looking over this, it appears that above rule does not have a class-type
assigned. Neither has SID 2184. Above is probably trojan-activity, I'm
not sure what class the RPC thingy (2184) is.

Regards,
Frank



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20031203/73f7b1e7/attachment.sig>


More information about the Snort-sigs mailing list