[Snort-users] New to snort

Johnno valentine at ...3655...
Mon Oct 1 14:38:03 EDT 2001


I am very new to snort.. only installed it a few days ago..

what I want snort to do if it picks up 

alert tcp any any -> any 80
(content:"cmd.exe";msg:"cmd.exe exploit";)

it will drop the connection end of story...

many thanks,
                        Johnno






More information about the Snort-users mailing list