[Snort-users] Snort rule to monitor for a specific user login

Nigel Houghton nhoughton at ...1935...
Thu Aug 13 11:04:16 EDT 2009


On Thu, Aug 13, 2009 at 10:54 AM, Jesse Lands<cryptograffiti at ...11827...> wrote:
> Is it possible to create a snort trigger for any time a specific username is
> used to attempt a login over the network?  I've never created a snort rule
> before so if it's in the FAQ I apologize.
>
> Thanks
> Jesse
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus
> on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>


If you can see the data in network traffic, you can write a rule to find it.

-- 
Nigel Houghton
Head Mentalist
SF VRT
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/




More information about the Snort-users mailing list