my flow rule doesn't work

Xing Star via Snort-sigs <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CA+JeoK-3J3DKMJkNZqWZUEJxOoHkk6U_PpPB-O9e0C9GrvrEJQ@mail.gmail.com>
I make a rule to detect this pcap.But it seems not work at all.How can I do?
Rule:
alert tcp any any -> any any
(msg:"TLS";flow:established,to_server;cotent:"|16 03 03|";content:"|14 03
03|";content:"|16 03 03|";content:"|17 03 03|";sid:87654321;rev:2;)
I think it will work properly  ,but it can match to 14 03 03 16 03 03, it
can't match 17 03 03 .
And if the rule like this :alert tcp any any -> any any
(msg:"TLS";flow:established,to_server;cotent:"|16 03 03|";content:"|14 03
03|";content:"|16 03 03|";content:"|16 03 03|";sid:87654321;rev:2;) , it
can match from head.
I don't know why . Should I need to modify config file?
Please help me ,thanks very much
[image: image.png]
[image: image.png]
[image: image.png]

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
image.png (image/png, 118.8 KB) - not displayed
image.png (image/png, 127.5 KB) - not displayed
image.png (image/png, 145.6 KB) - not displayed
rule-testflow.pcap (application/octet-stream, 4.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.