Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] How can write rule with a range IP? |
|---|---|
| Date: | Mon, 28 Jan 2008 14:05:10 -0800 |
And, generally speaking, the use of variables is preferable to hard-coding IP addresses into rules, e.g.: var $SOME_NET [10.0.0.1,10.0.0.5,10.0.1.0/24] alert $SOME_NET any -> any any ........ CP Joel Esler wrote:
Either seperate the multiple IP's that are in "[ ]" brackets with commas, or if all your IP's are consecutive, you may use CIDR notation. J On Jan 27, 2008, at 3:15 AM, bahamin takhtaei wrote:Hi, Please tell me How can write a rule in snort with a range IP, e.g. alert icmp [10.0.0.21 : 151.43.23.76 , 12.5.6.7] any -> any (sid:2000000;) I checked this rule and found that snort only checks the first boundary of range (10.0.0.21) in packets! Thanks ------------------------------------------------------------------------ Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now. <http://us.rd.yahoo.com/evt=51733/*http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ-------------------------------------------------------------------------This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/_______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users------------------------------------------------------------------------ ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ ------------------------------------------------------------------------ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] FATAL ERROR: Cannot check flow connection for non-TCP traffic, JJC |
|---|---|
| Next by Date: | [Snort-users] Barynard compile gives "unable to find mysql headers mysql.h, sudhakar govindavajhala |
| Previous by Thread: | Re: [Snort-users] How can write rule with a range IP?, Joel Esler |
| Next by Thread: | [Snort-users] flexresp2 breaks 2.8.0.1?, Jason Haar |
| Indexes: | [Date] [Thread] [Top] [All Lists] |