[Snort-sigs] Regarding rule 491 INFO FTP Bad login

J-H. Johansen corinth at ...121...
Mon Jul 14 04:47:32 EDT 2003


Hi,

When the 491 rule logs it logs the destination and source addresses.

Since the rule actually kicks into effect when destination fails to login shouldn't the log output then switch destination with source and source with destination ?

Does snort support this kind of switching ?

J-H Johansen
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20030714/b808674c/attachment.html>


More information about the Snort-sigs mailing list