[Snort-sigs] port list

Brian bmc at ...95...
Fri Feb 28 14:45:03 EST 2003


On Fri, Feb 28, 2003 at 04:52:53PM -0500, JimF wrote:
> Rules support IP lists such as [10.0.0.5,24.0.0.3,64.0.0.4]
> Is it possible to do the same thing with ports such as
> ![25,80] meaning all traffic except smtp and web?
> If it is not possible now is there any chance this
> capability will be added to future version?

It will be in snort in future versions.  For now, you can fake it 
if you are using the default rulesets.

var HTTP_PORTS 80
include web-cgi.rules
var HTTP_PORTS 88
include web-cgi.rules




More information about the Snort-sigs mailing list