[Snort-users] Suggestion on Snort Rule to Block forum junk post

George cc_to at ...8113...
Thu Apr 18 06:51:04 EDT 2013


Hello All,
 
May I ask for your experise -
 
How to create a Snort rule which block incoming HTTP Post request, 
where the post field - message - contains the following pattern
 
...[url=http...[url=http...[url=http...[url=http...
 
... = wildcard
 
It intends to block phpBB too-many junk post in the forum.
 
Thank you very much for your kind attention.

Regards
George
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130418/9ac2c6f7/attachment.html>


More information about the Snort-users mailing list