[Snort-sigs] Snort - problem

eirinina at ...3092... eirinina at ...3092...
Sun Jun 12 02:37:39 EDT 2005


I have the following problem: 
I use Snort as a NIDS in order to monitor a single host. But I have a problem with HTML POST GET attempts. I want to have an alert every time a password transfers from my host to internal or external network. So, I created a file named "password.rules" and I wrote the following rule: 
alert tcp any any -> any any (content: "password";)

However, this rule doesn't work hence it doesn't catch password attempts. Do you know what's wrong with the rule or where might the problem is?

Thank you,

More information about the Snort-sigs mailing list