[Snort-users] Creating a new rule

David Cintron david at ...8635...
Thu Apr 17 07:26:03 EDT 2003


I'm having problems picking up an alert from a rule i created. Here is the
rule.

alert tcp any any -> IP ADDRESS/32 80 (uricontent:"\>\"";
msg:"Vignette Attack";)

Here is what i am using to see if snort will pick it up.


telnet IP ADDRESS 80 <Return>
GET /foo/bar?x=""""">>>> HTTP/1.0 <Return>
<Return>

Any Help would be great.





More information about the Snort-users mailing list