<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detect string in the payload in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/detect-string-in-the-payload/m-p/545909#M90231</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide a little more detail as to how you tested and what you mean by "it does not seem to work".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Mar 2006 16:16:25 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2006-03-22T16:16:25Z</dc:date>
    <item>
      <title>Detect string in the payload</title>
      <link>https://community.cisco.com/t5/network-security/detect-string-in-the-payload/m-p/545908#M90229</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to configure my sensor such that it sends a reset packet if it detect string "ool" in the payload. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the sensor should send the original packet from the attacker included in the alert. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a custome signature with STRING.TCP, but it does not seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/detect-string-in-the-payload/m-p/545908#M90229</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2019-03-10T09:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Detect string in the payload</title>
      <link>https://community.cisco.com/t5/network-security/detect-string-in-the-payload/m-p/545909#M90231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide a little more detail as to how you tested and what you mean by "it does not seem to work".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Mar 2006 16:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/detect-string-in-the-payload/m-p/545909#M90231</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-03-22T16:16:25Z</dc:date>
    </item>
  </channel>
</rss>

