Solved

Snort, Modify snort rule "WEB-CGI finger access" to ignore destination IP

Posted on 2010-09-14
5
1,105 Views
Last Modified: 2013-11-16
How do I change the snort rule to ignore when destination IP (e.g. desIP is 10.11.12.13)

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-CGI finger access"; flow:to_server,established; uricontent:"/finger"; nocase; metadata:service http; reference:arachnids,221; reference:cve,1999-0612; reference:nessus,10071; classtype:attempted-recon; sid:839; rev:8;)
0
Comment
Question by:rgbcof
  • 3
  • 2
5 Comments
 

Author Comment

by:rgbcof
ID: 33674300
More info on the question:
Source IP          Dest IP           Port
10.11.11.11      10.11.12.13      80         Snort         WEB-CGI finger access

So I want this SNORT rule to ignore when DestIP is 0.11.12.13
0
 
LVL 3

Expert Comment

by:gorhon
ID: 33674310
Hello,

First find snort attack id number for this attack.

Please open the threshold.conf file. and goto last line and

suppress gen_id 122, sig_id 27, track by_src, ip 192.168.1.0/24

(gen id 122 and signature id 27 not collect from the 192.168.1.0/24 network)




14.09.jpg
0
 

Author Comment

by:rgbcof
ID: 33674377
How do you modify the SNORT rule?
0
 
LVL 3

Accepted Solution

by:
gorhon earned 125 total points
ID: 33674450
Sorry, this your rule. But how change rules? Many many hardwork. Good luck.

suppress gen_id xxxx, sig_id yyy, track by_dst, ip 10.11.12.13/32


0
 

Author Closing Comment

by:rgbcof
ID: 33674844
Great, thanks for the lead.
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question