[Snort-users] excludes some Local IPs

Jesús Gálvez jesuxgalvez at ...11031...
Wed Aug 9 06:54:03 EDT 2006


Is correct the next rule?

alert tcp $EXTERNAL_NET any -> $HOME_NET AND !99.99.99.0/24 139 (msg:"NETBIOS NT NULL session"; flow:to_server,established; content:"|00 00 00 00|W|00|i|00|n|00|d|00|o|00|w|00|s|00| |00|N|00|T|00| |00|1|00|3|00|8|00|1"; reference:arachnids,204; reference:bugtraq,1163; reference:cve,2000-0347; classtype:attempted-recon; sid:530; rev:10;)

I restart snort with this rule and don´t show me error enough.

 		
---------------------------------

LLama Gratis a cualquier PC del Mundo.
Llamadas a fijos y móviles desde 1 céntimo por minuto.
http://es.voice.yahoo.com
 		
---------------------------------

LLama Gratis a cualquier PC del Mundo.
Llamadas a fijos y móviles desde 1 céntimo por minuto.
http://es.voice.yahoo.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20060809/a60cc5e3/attachment.html>


More information about the Snort-users mailing list