About
Pricing
Community
Teams
Start Free Trial
Log in
NYGiantsFan
asked on
11/25/2013
question regarding snort rule
Hi,
I am somewhat new to reading snort rule sets. Can someone translate this for me. Thanks.
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Sogoul.com Spyware User-Agent (SogouIMEMiniSetup?)"; flow:established,to_server
; content:"User-Agent|3a| SogouIME?"; http_header; reference:url,doc.emerging
threats.ne
t/2008500;
classtype:trojan-activity;
sid:2008500; rev:6;)
Networking
Security
1
1
Last Comment
Rich Rumble
8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
Rich Rumble
11/25/2013
THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck