[Snort-users] Filter SYN ACK

Warrick FitzGerald wfitzgerald at ...4728...
Tue Jan 29 20:06:13 EST 2002

Hi All,

Im hoping you guys have a better idea than some very tedious ones that I
have tried.

I am trying to filter HTTP draffic, which is easy enough, but I would only
like to capture packets that contain application layer data ie. a GET or
POST etc. does anyone know an easy way / basic filter than can do this for
me ?


More information about the Snort-users mailing list