[Snort-sigs] Rule thoughts
jlay at ...3266...
Thu Sep 6 15:22:56 EDT 2012
On 2012-09-06 13:14, Joel Esler wrote:
> Think in the reverse order.
> content:"mailto:<"; content:!">"; distance:0; within:1500;
> Although you if you have a mailto that is longer than say... 100,
> that's probably bad.
> On Sep 6, 2012, at 3:08 PM, James Lay <jlay at ...3266...>
>> Hey all,
>> So...been keeping my eye on:
>> and was interested in this portion to have Snort look at:
>> font-family: "MyFont";
>> src: url(mailto:xxx<... approximately 2,020 characters removed
>> My thought was to do something like:
>> content: "mailto:<"; content: ">"; within: 1500;
>> or would offset be more appropriate? Any pointers would
Thanks for fixing my thinking Joel :) Guess maybe a more generic rule
would work as well..."Unusually long mailto detected" or something.
I'll see what I can come up with.
More information about the Snort-sigs