Home page logo

snort logo Snort mailing list archives

Re: [SPAM] Re: DNS Packets
From: Joel Esler <jesler () sourcefire com>
Date: Mon, 3 Jun 2013 16:56:52 -0400

On Jun 3, 2013, at 3:11 PM, rmkml <rmkml () yahoo fr> wrote:

Please remove "priority:3;"

Doesn't need to if he doesn't want to.

and please change sid to short like 10000002.

Again, up to him and his numbering sequence.  Nothing wrong with that.

Info: change var to ipvar.

Depends on his version of Snort.

Please check snort cmd line with "-k none" for testing only.

Please check if you need "flow:from_server,established;" on your dns rule.

Don't need established if you are doing a UDP rule.

Still doesn't solve his problems.

He's looking for someone to provide him the answer.  

Give a man the answer, and he’ll only have a temporary solution. Teach him the principles that led you to that answer, 
and he will be able to create his own solutions in the future.

Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
How ServiceNow helps IT people transform IT departments:
1. A cloud service to automate IT design, transition and operations
2. Dashboards that offer high-level views of enterprise services
3. A single system of record for all IT processes
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]