Re: example of decoder and preprocessor rules

"Al Lewis (allewi)" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
The snort download has examples included. The example is also here: http://manual.snort.org/node40.html

Also… you should  checkout snort++ (Snort3) which has made it easier to make custom plugin modules.


Albert Lewis
QA Software Engineer
SOURCEfire, Inc. now part of Cisco
9780 Patuxent Woods Drive
Columbia, MD 21046
Phone: (office) 443.430.7112
Email: [email protected]

From: M. Ridwan Zalbina [mailto:[email protected]]
Sent: Friday, August 21, 2015 12:48 AM
To: [email protected]
Subject: [Snort-devel] example of decoder and preprocessor rules

Hello everyone,
I do a research about detection system based on snort for detecting
web attack(http protocol) like xss and injection(sqli)
which combine preprocessor and detection engine in snort.

In detection engine i already made it and use some approach using
regular expression
I want to make some rule or decision about packet anomaly in http_inspect preprocessor.

I've already read about the example of DECODER AND PREPROCESSOR rules, and it's just show one example...


For that reason, is anybody have a suggestion about this or anyone made this before.. ?


Sorry for my bad words..
M. Ridwan Zalbina

------------------------------------------------------------------------------

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.