[Snort-sigs] TCP sweeps

Frank Knobbe frank at ...1978...
Tue Dec 14 20:22:06 EST 2004

On Tue, 2004-12-14 at 13:14, James Riden wrote:
> alert tcp $HOME_NET !21:443 -> $EXTERNAL_NET !80 (msg:"BLEEDING-EDGE

Could someone please explain to me the reasoning for !21:443? It's not
related to ignoring data in passive FTP streams since that's port 20. I
just can't make any sense out of the above brain-twister.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20041214/6c7eb6dc/attachment.sig>

More information about the Snort-sigs mailing list