example of decoder and preprocessor rules
"M. Ridwan Zalbina" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <CABMSmek3oQFhfgeCb=doAFLhxx_o4FxgEXGT7FMBTXbi+GJXPw@mail.gmail.com> |
Hello everyone, I do a research about detection system based on snort for detecting web attack(http protocol) like xss and injection(sqli) which combine preprocessor and detection engine in snort. In detection engine i already made it and use some approach using regular expression I want to make some rule or decision about packet anomaly in http_inspect preprocessor. I've already read about the example of DECODER AND PREPROCESSOR rules, and it's just show one example... For that reason, is anybody have a suggestion about this or anyone made this before.. ? Sorry for my bad words.. M. Ridwan Zalbina ------------------------------------------------------------------------------ _______________________________________________ Snort-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/snort-devel Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel Please visit http://blog.snort.org for the latest news about Snort!