waldo kitty wkitty42 at ...3507...
Fri Feb 15 22:53:52 EST 2013

On 2/15/2013 09:49, alex dina wrote:
> I am new to writing Snort rules,


> is there a manual, book or URL you can recommend to brush up on this?

others have responded with what i would also point to... snort rules are not 
that hard to decipher ;)

> what about the sid:4200455 in the rule?

that is simply an ID number... they can change when one submits their rules to 
those who may publish them... it is just a number which is used to correlate the 
alerts generated by it... outside of that, it really doesn't mean all that much...

> what is there to explain? it is very simple... it is looking for content blocks
> of the following...
> GET /
> .asp?est=
> &hn=
> &ha=
> all must appear in the same packet...

