SNORT RULES

pts.
Tags:
Intrusion management
I am trying to define a snort rule that will detect the word "spam" in the subject field of an email. So far I have tried alert tcp any any -> any 25 (content:"Spam" nocase; msg:"Email traffic logged!";) But this is not filtering out only the emails that I want. ANy help would be much appreciated. Thanks.

Answer Wiki

Thanks. We'll let you know when a new response is added.

First off, you’d probably be better off by joining the Snort users email list at sourceforge.net. Yours is a common type of question there.

Secondly, I’m curious as to what you hope to accomplish by doing this.

I use Snort myself, but my rule-writing is weak at this point.

Bob

Discuss This Question: 1  Reply

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
  • Bobkberg
    First off, you'd probably be better off by joining the Snort users email list at sourceforge.net. Yours is a common type of question there. Secondly, I'm curious as to what you hope to accomplish by doing this. I use Snort myself, but my rule-writing is weak at this point. Bob
    1,070 pointsBadges:
    report

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following