[Snort-sigs] Snort - problem

Joel Esler eslerj at ...2420...
Sun Jun 12 06:43:31 EDT 2005

You don't have a msg in there. Consult your Snort documentation for the 
"msg" tag..

(Also, I don't think what you're trying to do will work with this rule...)

On 6/12/05, eirinina at ...3092... <eirinina at ...3092...> wrote:
> Hello,
> I have the following problem:
> I use Snort as a NIDS in order to monitor a single host. But I have a 
> problem with HTML POST GET attempts. I want to have an alert every time a 
> password transfers from my host to internal or external network. So, I 
> created a file named "password.rules" and I wrote the following rule:
> alert tcp any any -> any any (content: "password";)
> However, this rule doesn't work hence it doesn't catch password attempts. 
> Do you know what's wrong with the rule or where might the problem is?
> Thank you,
> Eirini
> -------------------------------------------------------
> This SF.Net <http://SF.Net> email is sponsored by: NEC IT Guy Games. How 
> far can you shotput
> a projector? How fast can you ride your desk chair down the office luge 
> track?
> If you want to score the big prize, get to know the little guy.
> Play to win an NEC 61" plasma display: http://www.necitguy.com/?r
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20050612/30237776/attachment.html>

More information about the Snort-sigs mailing list