[Snort-sigs] MS Exchange rule

Hugo van der Kooij hvdkooij at ...481...
Wed Jul 23 22:34:09 EDT 2003


On Wed, 23 Jul 2003, Kraus, Thorsten wrote:

> does a rule exist, where I can log wrong logins to my Microsoft 
> Exchange server?

In all likelyhood this is encrypted traffic and it will be too hard to 
find a working definition.

We are talking about flexible port usage (not a fixed network port) and 
encrypted data traffic.

Hugo.

-- 
 All email sent to me is bound to the rules described on my homepage.
    hvdkooij at ...481...		http://hvdkooij.xs4all.nl/
	    Don't meddle in the affairs of sysadmins,
	    for they are subtle and quick to anger.





More information about the Snort-sigs mailing list