[Snort-sigs] rules and protocol URL

Nosnos nosnos94 at ...1123...
Mon Nov 10 05:53:13 EST 2003


Hi,

I want to know how to write a rule that only match traffic that correspond to HTTP protocol ... ? I know that often rules try to match the port 80, but I want a rules that detect http protocol and are not based on port number ....

(I want the same things for pop or stmp protocol) ...

thx a lot
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20031110/56fe04c8/attachment.html>


More information about the Snort-sigs mailing list