[Snort-users] [snort-user] About packet content

Mayur Patil ram.nath241089 at ...11827...
Thu Sep 5 05:11:23 EDT 2013

hello all,

      I have one question might be foolish......

      In snort rule we define content for packets

      like content:|00 36 90 23 08|

      is there anyway to know what content does incoming data is having

      before attack is performed ? Any prototype which defines specific
structure ?

      Seeking for guidance,

      Thanks !
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130905/4d5e2a5e/attachment.html>

More information about the Snort-users mailing list