[Snort-sigs] Matching host get and content
jlay at ...3266...
Mon Jul 9 12:29:38 EDT 2012
I'm not even sure where to look for this, but in layman's terms I want
to "match on http getting to a certain domain name and match some
content within, only when the two match alert". Is this a
stream_reassemble thing? Am I looking at something like:
flow:established,to_server; stream_reassemble;enable: content:bleh.com;
Thanks for any pointers.
More information about the Snort-sigs