Snort mailing list archives

SSH rules


From: "Dave Loutrel \(ACME\)" <dbl () acme-ent net>
Date: Tue, 27 Nov 2001 07:31:00 -0900

I am just beginning to play with snort.  After about 30 minutes of Googletime, trying to find some existing rules for 
SSH, I decided to ask for some help.

We're seeing a number of attempted ssh logins and would like to write some rules for snort to alert on these.  

Could someone point me in the right direction?

Thanks

Dave Loutrel

Current thread: