Snort mailing list archives

Snort Manual - 3.5.21 urilen


From: Eoin Miller <eoin.miller () trojanedbinaries com>
Date: Thu, 29 Dec 2011 03:24:32 +0000

---SNIP---
The following example will match URIs that are greater than 5 bytes and
less than 10 bytes:

urilen:5<>10;
---SNIP---


Seems weird that the operators work like:

urilen:min<>max

Seems like it should be the other way if you think of the less than and
greater than operators? More like:

urilen:max<>min;

Makes my brain think maxNumber-lessThan && greaterThan-minNumber;

urilen:10<>5;

-- Eoin

------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual 
desktops for less than the cost of PCs and save 60% on VDI infrastructure 
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: