[Snort-users] IP Address's in Rule

Mike McCabe mike at ...6998...
Wed Oct 9 11:36:05 EDT 2002


Thanks Everybody...

I think I understand the logic of this now...

Mike

----- Original Message -----
From: "Slighter, Tim" <tslighter at ...5174...>
To: "'Mike McCabe'" <mike at ...6998...>;
<snort-users at lists.sourceforge.net>
Sent: Wednesday, October 09, 2002 1:38 PM
Subject: RE: [Snort-users] IP Address's in Rule


> if you only wish to exclude those specific IP addresses, then you should
not
> need the $EXTERNAL_NET as it will alert for anything but the !x.x.x.x/32
> IP's.
> -----Original Message-----
> From: Mike McCabe [mailto:mike at ...6998...]
> Sent: Wednesday, October 09, 2002 10:57 AM
> To: snort-users at lists.sourceforge.net
> Subject: [Snort-users] IP Address's in Rule
>
>
> How do I include specific IP addresses in a rule.  Say I want to have
> certain IP addresses not looked at and still want the rule to use
> EXTERNAL_NET...  Something like:
>
> alert tcp [!X.Y.W.Z/32,!A.B.C.D/32,!E.F.G.H/32,$EXTERNAL_NET] any ->
> $HOME_NET 53 (msg:"DNS zone transfer"; content: "|00 00 FC|"; flags: A+;
> offset: 13; reference:arachnids,212; classtype:attempted-recon; sid:255;
> rev:2;)
>
> But it doesn't seem to work...
>
> Any help would be appreciated...
>
> Mike
>
>
>
> -------------------------------------------------------
> This sf.net email is sponsored by:ThinkGeek
> Welcome to geek heaven.
> http://thinkgeek.com/sf
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
>
> -------------------------------------------------------
> This sf.net email is sponsored by:ThinkGeek
> Welcome to geek heaven.
> http://thinkgeek.com/sf
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>





More information about the Snort-users mailing list