[Snort-users] newbie: http and uris

mosquitooth at ...158... mosquitooth at ...158...
Wed Apr 13 13:29:23 EDT 2005


I've got some (newbie) questions concerning http and especially URIs I
couldn't find an answert to - but nethertheless I do need the answers to
write snort rules with the "uricontent" keyword.

- What does the string "\....\" in an URI mean? There are some hints on
"directory transversal" - could someone explain this any further?

- Every whitespace character in an URI is replaced by a "+" when encoded to
html (correct?). Now, does snort remove this "+" when it decodes the http

- What is the standard decoding for snort? UTF7, UTF8, Unicode, ASCII...?

- Several papers I tried to read about the subject contain the term "regular
expression". What's this?

Greetings and thanks in advance,


+++ NEU: GMX DSL_Flatrate! Schon ab 14,99 EUR/Monat! +++

GMX Garantie: Surfen ohne Tempo-Limit! http://www.gmx.net/de/go/dsl

More information about the Snort-users mailing list