[Snort-users] snort 2.3.3 --enable-flexresp

hans rosa.schwein at ...12989...
Mon Apr 25 01:37:09 EDT 2005

hi all 

i tried the experimental feature '--enable-flexresp' for 
compiling snort 2.3.3 on solaris 9 ( both sparc and intel plattform ) 

the first tests did run well, the following rule did 
disconnect an incomming connection immediate:

alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; resp:rst_all; )

the next step was to modify this rule sligthly. the disconnect should 
only appear, if the word "hello" was seen, with this rule: 

alert tcp any any <> $HOME_NET 25 (msg:"HELLOon25"; content:"hello"; resp:rst_all; )

i telnet to port 25, key in "hello"  ( knowing it's not a smtp-dialog  ) 
and nothing happens. i get a logentry, so the rule is involved 
if the word "hello" is seen, but no disconnect. 

i searched a lot of time around the internet, but could find 
any advice, what the problem could be. 

every advice would be helpfully. 

just disconnecting any incomming connection could be the idea, a 
tcpwrapper could this job too. 

best regards 


More information about the Snort-users mailing list