Snort mailing list archives
Re: re: public snmp pass question
From: "Stephen Dunn" <sdunn () stephendunn com>
Date: Thu, 26 Jun 2003 19:59:23 -0700 (PDT)
alert udp any any -> any 161:162 (msg:"Non public SNMP access"; content: !"public";) The alert above should do the trick. No pass rule is really necessary here. All you need to do is use the ! operator on the "public" content string of your existing snort rule to tell snort not to alert if it sees "public" in the request. Steve
I would like to create a pass rule to pass snmp requests with a public community string from any to any but would like to see snmp requests with non-public community strings. Is it possible to create a rule that will pass the snmp public requests and alert on the non-public requests? regards, Lindsay Hunt Network Engineer Alstom Power phone 804-763-7239 mobile 804-334-1682 fax 804-763-7107 CONFIDENTIALITY : This e-mail and any attachments are confidential and may be privileged. If you are not a named recipient, please notify the sender immediately and do not disclose the contents to another person, use it for any purpose or store or copy the information in any medium. ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- re: public snmp pass question lindsay . hunt (Jun 26)
- Re: re: public snmp pass question Stephen Dunn (Jun 26)
