[Snort-sigs] Triggering a complex snort rule (packet forging)

Asiri Rathnayake asiri.rathnayake at ...2420...
Tue Apr 2 08:47:32 EDT 2013


Hi,


On Tue, Apr 2, 2013 at 1:31 PM, Jamie Riden <jamie.riden at ...2420...> wrote:

> You could look at grabbing a real packet and using tcpreplay maybe?
>

So, grab the packet from within the local network and then try to inject it
into the network (replay) from outside?

Sounds like a good idea, will give it a go.

Thanks!

- Asiri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20130402/710104ca/attachment.html>


More information about the Snort-sigs mailing list