[Snort-users] Creating a new rule

David Cintron david at ...8635...
Thu Apr 17 07:26:03 EDT 2003

I'm having problems picking up an alert from a rule i created. Here is the

alert tcp any any -> IP ADDRESS/32 80 (uricontent:"\>\"";
msg:"Vignette Attack";)

Here is what i am using to see if snort will pick it up.

telnet IP ADDRESS 80 <Return>
GET /foo/bar?x=""""">>>> HTTP/1.0 <Return>

Any Help would be great.

More information about the Snort-users mailing list