Snort mailing list archives
Re: Applying a rule on entire session
From: "Alex Butcher, ISC/ISYS" <Alex.Butcher () bristol ac uk>
Date: Wed, 08 Sep 2004 12:34:07 +0100
--On 08 September 2004 01:53 -0700 Dennis George <easyeinfo () yahoo com> wrote:
Hi,flowbits and looking for the FIN and/or RST flags?I mean to say that the rules should be applied to the reassembled data chunk of the entire session. The rule should not be applied to each packet coming.... instead after all the packet form a session then only apply that rule.........
<http://www.snort.org/docs/snort_manual/node10.html#SECTION00314200000000000000>
Regards Dennis
Best Regards, Alex. -- Alex Butcher: Security & Integrity, Personal Computer Systems Group Information Systems and Computing GPG Key ID: F9B27DC9 GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9 ------------------------------------------------------- This SF.Net email is sponsored by BEA Weblogic Workshop FREE Java Enterprise J2EE developer tools! Get your free copy of BEA WebLogic Workshop 8.1 today. http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Applying a rule on entire session Dennis George (Sep 07)
- Re: Applying a rule on entire session Alex Butcher, ISC/ISYS (Sep 08)
- Re: Applying a rule on entire session Dennis George (Sep 08)
- Re: Applying a rule on entire session Alex Butcher, ISC/ISYS (Sep 08)
- Re: Applying a rule on entire session Dennis George (Sep 08)
- <Possible follow-ups>
- RE: Applying a rule on entire session Mohammad Abdel Hady (Sep 08)
- Re: Applying a rule on entire session Alex Butcher, ISC/ISYS (Sep 08)