Re: About Sort Pattern Matching
"J. Hellenthal via Snort-devel" <[email protected]> Fri, 13 Sep 2019 06:40:03 -0500
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============3344060543493222823== Content-Type: multipart/alternative; boundary=Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7 Content-Transfer-Encoding: 7bit --Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable You could be hitting the dynamic .so rules. Off the top of my head loaded vi= a either the config or dynamically from /usr/local/.... IIRC --=20 J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a= lot about anticipated traffic volume. > On Sep 13, 2019, at 02:17, M=C3=BB=C4=A7=C4=85=C9=B1=C9=B1=C9=90=C9=96 Y=C4= =83=C5=9F=D1=97=D1=93 via Snort-devel <[email protected]> wrote: >=20 > =EF=BB=BF > Dear All, > Can you guys tell me where exactly [function in which file] does snort per= forms "content" option match of a rule with input packet data? I have disabl= ed all the rules but one in local.rules which has "content:Bahria" rule opti= on and want to calculate time for that single match against varying length p= ackets. >=20 > --=20 > Regards,=20 > Muhammad Yasir > _______________________________________________ > Snort-devel mailing list > [email protected] > https://lists.snort.org/mailman/listinfo/snort-devel >=20 > Please visit http://blog.snort.org for the latest news about Snort! --Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto">You could be hitting the dynamic .so rules.= Off the top of my head loaded via either the config or dynamically from /us= r/local/.... IIRC<br><br><div dir=3D"ltr"><div><span style=3D"background-col= or: rgba(255, 255, 255, 0);">-- </span></div><div><span style=3D"backgr= ound-color: rgba(255, 255, 255, 0);"> J. Hellenthal</span></div><div><s= pan style=3D"background-color: rgba(255, 255, 255, 0);"><br></span></div><sp= an style=3D"background-color: rgba(255, 255, 255, 0);">The fact that there's= a highway to Hell but only a stairway to Heaven says a lot about anticipate= d traffic volume.</span></div><div dir=3D"ltr"><br><blockquote type=3D"cite"= >On Sep 13, 2019, at 02:17, M=C3=BB=C4=A7=C4=85=C9=B1=C9=B1=C9=90=C9=96 Y=C4= =83=C5=9F=D1=97=D1=93 via Snort-devel <[email protected]> wr= ote:<br><br></blockquote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF= =BB=BF<div dir=3D"ltr">Dear All,<br>Can you guys tell me where exactly [func= tion in which file] does snort performs "content" option match of a rule wit= h input packet data? I have disabled all the rules but one in local.rules wh= ich has "content:Bahria" rule option and want to calculate time for that sin= gle match against varying length packets.<br clear=3D"all"><div><br></div>--= <br><div dir=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_sign= ature"><div dir=3D"ltr">Regards, <br><font face=3D"comic sans ms, sans-= serif" color=3D"#444444"><b>Muhammad Yasir</b></font></div></div></div> <span>_______________________________________________</span><br><span>Snort-= devel mailing list</span><br><span>[email protected]</span><br><sp= an>https://lists.snort.org/mailman/listinfo/snort-devel</span><br><span></sp= an><br><span>Please visit http://blog.snort.org for the latest news about Sn= ort!</span><br></div></blockquote></body></html>= --Apple-Mail-73F22271-B078-4565-B361-E2C7C6F77DA7-- --===============3344060543493222823== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============3344060543493222823==--