example of decoder and preprocessor rules

"M. Ridwan Zalbina" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CABMSmek3oQFhfgeCb=doAFLhxx_o4FxgEXGT7FMBTXbi+GJXPw@mail.gmail.com>
Hello everyone,
I do a research about detection system based on snort for detecting
web attack(http protocol) like xss and injection(sqli)
which combine preprocessor and detection engine in snort.

In detection engine i already made it and use some approach using
regular expression
I want to make some rule or decision about packet anomaly in http_inspect
preprocessor.


I've already read about the example of DECODER AND PREPROCESSOR rules, and
it's just show one example...


For that reason, is anybody have a suggestion about this or anyone made
this before.. ?



Sorry for my bad words..
M. Ridwan Zalbina

------------------------------------------------------------------------------

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.