[Snort-users] Any way to do something like "Flowbits, " but for other than a TCP stream?

M. Shirk shirkdog_list at ...125...
Fri Nov 16 11:15:48 EST 2007

You could do a chain of flowbits sure.

make another rule, set a flowbit:proto103sucks; on the proto 77 packet in the first signature, then check the proto103sucks bit on the proto103 packet. 

' or 1=1-- 


> Date: Thu, 15 Nov 2007 16:02:03 -0500
> From: Stephen.Bachelor.ctr at ...14240...
> To: snort-users at lists.sourceforge.net
> Subject: [Snort-users] Any way to do something like "Flowbits,	" but for other than a TCP stream?
> My problem is false positives on rule 1:2189, Bad-Traffic IP Proto 103.
> To exploit the vulnerability, one must send 4 packets, with successive
> protocol types: 53, 55, 77, and 103. The Snort rule only seems to look
> for proto_id: 103, and it's creating thousands of false positives for
> me. How can I make it trigger on 103 only if there's been a proto_id: 77
> to the same destination, one packet earlier? As far as I can tell,
> threshholding rules aren't quite flexible enough to help.
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Microsoft
> Defy all challenges. Microsoft(R) Visual Studio 2005.
> http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users

Climb to the top of the charts!  Play Star Shuffle:  the word scramble challenge with star power.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20071116/568ecc55/attachment.html>

More information about the Snort-users mailing list