[Snort-sigs] pass rules

edmund.li at ...1981... edmund.li at ...1981...
Sat Oct 25 07:13:04 EDT 2003


Dear all, 

May I know how can I make the pass rules ?

e.g 

SCAN UPnP service discover attempt, it happens for all XP PC ... 

Edmund




alert udp $EXTERNAL_NET any -> $HOME_NET 1900 (msg:"SCAN UPnP service 
discover attempt"; content:"M-SEARCH "; offset:0; depth:9; 
content:"ssdp\:discover"; classtype:network-scan; sid:1917; rev:4;) 



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20031025/d5e7e4c4/attachment.html>


More information about the Snort-sigs mailing list