Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] rule for Non-SSL traffic on SSL port? |
|---|---|
| Date: | Fri, 16 Jun 2006 07:53:04 -0500 |
Moderator: 2nd try, this time as registered user.
What I'm trying to accomplish can't be done with the commercial IPS we
currently use. I don't know a lot about Snort, and thought I'd see if it
might be up to the task.
Basically, I'm looking for a solution to alert me when a session on TCP
port 443 is not actually SSL. I want at most a single alarm per TCP
session. At a conceptual level, the solution would look for the SSL
handshake early in a TCP session and alert if it was not seen. Or
something like that anyway. Can this be done with Snort?
Thanks,
Matt
-----Message Disclaimer-----
This e-mail message is intended only for the use of the individual or
entity to which it is addressed, and may contain information that is
privileged, confidential and exempt from disclosure under applicable law.
If you are not the intended recipient, any dissemination, distribution or
copying of this communication is strictly prohibited. If you have
received this communication in error, please notify us immediately by
reply email to Connect@principal.com and delete or destroy all copies of
the original message and attachments thereto. Email sent to or from the
Principal Financial Group or any of its member companies may be retained
as required by law or regulation.
Nothing in this message is intended to constitute an Electronic signature
for purposes of the Uniform Electronic Transactions Act (UETA) or the
Electronic Signatures in Global and National Commerce Act ("E-Sign")
unless a specific statement to the contrary is included in this message.
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Sourcefire VRT |
|---|---|
| Next by Date: | [Snort-sigs] Sid 1893 FP, Jon Hart |
| Previous by Thread: | [Snort-sigs] Rule for identifying all trafic except the specefied one, Rajkumar S |
| Next by Thread: | Re: [Snort-sigs] rule for Non-SSL traffic on SSL port?, Lorine Ruotolo |
| Indexes: | [Date] [Thread] [Top] [All Lists] |