[Snort-users] Create rule for tcp/445 and IPC$ access

Mikael Bohlin Mikael.Bohlin at ...9638...
Fri Jul 11 10:58:22 EDT 2003


Does anyone know how to build a rule for Snort 2.0 that detects
\IPC$ access over tcp/445 (MS fileharing with Win2K)

What's the tric? Anyone already written a rule for this?


Regards,
Mikael




More information about the Snort-users mailing list