[Snort-users] snort 2.3.3 --enable-flexresp
rosa.schwein at ...12989...
Mon Apr 25 01:37:09 EDT 2005
i tried the experimental feature '--enable-flexresp' for
compiling snort 2.3.3 on solaris 9 ( both sparc and intel plattform )
the first tests did run well, the following rule did
disconnect an incomming connection immediate:
alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; resp:rst_all; )
the next step was to modify this rule sligthly. the disconnect should
only appear, if the word "hello" was seen, with this rule:
alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; content:"hello"; resp:rst_all; )
i telnet to port 25, key in "hello" ( knowing it's not a smtp-dialog )
and nothing happens. i get a logentry, so the rule is involved
if the word "hello" is seen, but no disconnect.
i searched a lot of time around the internet, but could find
any advice, what the problem could be.
every advice would be helpfully.
just disconnecting any incomming connection could be the idea, a
tcpwrapper could this job too.
More information about the Snort-users