[Snort-users] Fwd: [snort-user] About packet content

Mayur Patil ram.nath241089 at ...11827...
Fri Sep 6 01:52:14 EDT 2013


      I have one question might be foolish......

      In snort rule we define content for packets

      like content:|00 36 90 23 08|

      is there anyway to know what content does incoming data is having

      before attack is performed ? Any prototype which defines specific
structure ?

      Seeking for guidance,

      Thanks !
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130906/d8292a3f/attachment.html>

More information about the Snort-users mailing list