[Snort-sigs] Question about a Snort rule
miso.patel at ...2420...
Fri Feb 25 10:21:14 EST 2011
My engineers are having trouble with a custom rule:
alert udp $HOME_NET any -> $EXTERNAL_NET any (msg:"iPad related HTTP
request"; content:"iPad"; http_uri; nocase; flags:S;
Any help would be appreciated. The rule does not seem to be alerting
for some reason and I think this could be a bug with Snort.
More information about the Snort-sigs