[Snort-users] Questions (and bug report?) about tagging

Martin Olsson elof at ...6680...
Mon Aug 26 08:32:39 EDT 2002

I'm playing around with the tag option and don't get the expected result.

Machine A (flash - is running FreeBSD 4.6 and snort 1.8.7.
I have setup inetd to listen on port 80 with this script:

echo 'My server on port 80'
read VAR1
echo 'Here is a long listing of files'
ls -l /usr/lib
read VAR2
echo 'Now that should have triggered a couple of packets'
exit 0

I use this rule:
alert tcp any any -> any 80 (msg:"php.cgi access";flags:A+; uricontent:"/php.cgi"; nocase;
classtype:attempted-recon; sid:824; rev:6; tag:host,30,seconds,dst;)

More information about the Snort-users mailing list