Re: About Sort Pattern Matching

"J. Hellenthal via Snort-devel" <[email protected]> Fri, 13 Sep 2019 06:40:03 -0500
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
--===============3344060543493222823==
Content-Type: multipart/alternative; boundary=Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7
Content-Transfer-Encoding: 7bit


--Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

You could be hitting the dynamic .so rules. Off the top of my head loaded vi=
a either the config or dynamically from /usr/local/.... IIRC

--=20
 J. Hellenthal

The fact that there's a highway to Hell but only a stairway to Heaven says a=
 lot about anticipated traffic volume.

> On Sep 13, 2019, at 02:17, M=C3=BB=C4=A7=C4=85=C9=B1=C9=B1=C9=90=C9=96 Y=C4=
=83=C5=9F=D1=97=D1=93 via Snort-devel <[email protected]> wrote:
>=20
> =EF=BB=BF
> Dear All,
> Can you guys tell me where exactly [function in which file] does snort per=
forms "content" option match of a rule with input packet data? I have disabl=
ed all the rules but one in local.rules which has "content:Bahria" rule opti=
on and want to calculate time for that single match against varying length p=
ackets.
>=20
> --=20
> Regards,=20
> Muhammad Yasir
> _______________________________________________
> Snort-devel mailing list
> [email protected]
> https://lists.snort.org/mailman/listinfo/snort-devel
>=20
> Please visit http://blog.snort.org for the latest news about Snort!

--Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto">You could be hitting the dynamic .so rules.=
 Off the top of my head loaded via either the config or dynamically from /us=
r/local/.... IIRC<br><br><div dir=3D"ltr"><div><span style=3D"background-col=
or: rgba(255, 255, 255, 0);">--&nbsp;</span></div><div><span style=3D"backgr=
ound-color: rgba(255, 255, 255, 0);">&nbsp;J. Hellenthal</span></div><div><s=
pan style=3D"background-color: rgba(255, 255, 255, 0);"><br></span></div><sp=
an style=3D"background-color: rgba(255, 255, 255, 0);">The fact that there's=
 a highway to Hell but only a stairway to Heaven says a lot about anticipate=
d traffic volume.</span></div><div dir=3D"ltr"><br><blockquote type=3D"cite"=
>On Sep 13, 2019, at 02:17, M=C3=BB=C4=A7=C4=85=C9=B1=C9=B1=C9=90=C9=96 Y=C4=
=83=C5=9F=D1=97=D1=93 via Snort-devel &lt;[email protected]&gt; wr=
ote:<br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=
=BB=BF<div dir=3D"ltr">Dear All,<br>Can you guys tell me where exactly [func=
tion in which file] does snort performs "content" option match of a rule wit=
h input packet data? I have disabled all the rules but one in local.rules wh=
ich has "content:Bahria" rule option and want to calculate time for that sin=
gle match against varying length packets.<br clear=3D"all"><div><br></div>--=
 <br><div dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_sign=
ature"><div dir=3D"ltr">Regards,&nbsp;<br><font face=3D"comic sans ms, sans-=
serif" color=3D"#444444"><b>Muhammad Yasir</b></font></div></div></div>
<span>_______________________________________________</span><br><span>Snort-=
devel mailing list</span><br><span>[email protected]</span><br><sp=
an>https://lists.snort.org/mailman/listinfo/snort-devel</span><br><span></sp=
an><br><span>Please visit http://blog.snort.org for the latest news about Sn=
ort!</span><br></div></blockquote></body></html>=

--Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7--

--===============3344060543493222823==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============3344060543493222823==--