Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Testing snort rules

Posted on 2010-11-16
1
Medium Priority
?
1,036 Views
Last Modified: 2013-11-29
When designing a packet to test snort rules, does that packet need to contain all the content listed in the rule. For example a rule that has content:"|C8 4F 32 4B 70 16 D3 01 12 78 5A 47 BF 6E E1 88|"; content:"|00 2E 00 2E 00 5C 00 2E 00 2E 00 5C|"; flags:A+; etc.....?

Thanks
0
Comment
Question by:progjm
1 Comment
 
LVL 65

Accepted Solution

by:
btan earned 2000 total points
ID: 34152965
check out 2.3.9  Content

@ http://ebook.security-portal.cz/book/snort/writing_rules/chap2.html

Whenever a content option pattern match is performed, the Boyer-Moore pattern match function is called and the (rather computationally expensive) test is performed against the packet contents. If data exactly matching the argument data string is contained anywhere within the packet's payload, the test is successful and the remainder of the rule option tests are performed. Be aware that this test is case sensitive.

Also note option such as 2.3.10  Offset, 2.3.11  Depth and 2.3.12  Nocase that would impact the content matching. 2.3.23  Content-list would be of interest as well as it allows multiple content strings to be specified in the place of a single content option
0

Featured Post

New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article covers the basics of data encryption, what it is, how it works, and why it's important. If you've ever wondered what goes on when you "encrypt" data, you can look here to build a good foundation for your personal learning.
This article is about my experience upgrading my consulting machine to Windows 10 Version 1709 (The Fall 2017 Creator Update)
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question