<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS custom signature: HTTP not found in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709400#M92309</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much, it works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Sep 2006 15:37:47 GMT</pubDate>
    <dc:creator>csiszerakos2</dc:creator>
    <dc:date>2006-09-26T15:37:47Z</dc:date>
    <item>
      <title>IPS custom signature: HTTP not found</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709396#M92302</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to create a signature which fires when a  server reports HTTP Not found.&lt;/P&gt;&lt;P&gt;For testing purposes I have used space ([\x20]) for matching regexp. It does not work. When I &lt;/P&gt;&lt;P&gt;set the direction from "from-service" to "to-service" it works. Does someone have an idea? &lt;/P&gt;&lt;P&gt;There are no filters. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signature is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   sig-id: 60008&lt;/P&gt;&lt;P&gt;   subsig-id: 0&lt;/P&gt;&lt;P&gt;   -----------------------------------------------&lt;/P&gt;&lt;P&gt;      alert-severity: medium default: medium&lt;/P&gt;&lt;P&gt;      sig-fidelity-rating: 100 default: 75&lt;/P&gt;&lt;P&gt;      promisc-delta: 10 default: 0&lt;/P&gt;&lt;P&gt;      sig-description&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;         sig-name: HTTP not found v2 default: My Sig&lt;/P&gt;&lt;P&gt;         sig-string-info: HTTP not found default: My Sig Info&lt;/P&gt;&lt;P&gt;         sig-comment: Sig Comment default: Sig Comment&lt;/P&gt;&lt;P&gt;         alert-traits: 0 default: 0&lt;/P&gt;&lt;P&gt;         release: custom default: custom&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;      engine&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;         string-tcp&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            event-action: produce-alert default: produce-alert&lt;/P&gt;&lt;P&gt;            strip-telnet-options: false default: false&lt;/P&gt;&lt;P&gt;            specify-min-match-length&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;               no&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;            regex-string: [\x20]&lt;/P&gt;&lt;P&gt;            service-ports: 80&lt;/P&gt;&lt;P&gt;            direction: from-service default: to-service&lt;/P&gt;&lt;P&gt;            specify-exact-match-offset&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;               no&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;                  specify-max-match-offset&lt;/P&gt;&lt;P&gt;                  -----------------------------------------------&lt;/P&gt;&lt;P&gt;                     no&lt;/P&gt;&lt;P&gt;                     -----------------------------------------------&lt;/P&gt;&lt;P&gt;                     -----------------------------------------------&lt;/P&gt;&lt;P&gt;                  -----------------------------------------------&lt;/P&gt;&lt;P&gt;                  specify-min-match-offset&lt;/P&gt;&lt;P&gt;                  -----------------------------------------------&lt;/P&gt;&lt;P&gt;                     no&lt;/P&gt;&lt;P&gt;                     -----------------------------------------------&lt;/P&gt;&lt;P&gt;                     -----------------------------------------------&lt;/P&gt;&lt;P&gt;                  -----------------------------------------------&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;            swap-attacker-victim: false default: false&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;      event-counter&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;         event-count: 1 default: 1&lt;/P&gt;&lt;P&gt;         event-count-key: Axxx default: Axxx&lt;/P&gt;&lt;P&gt;         specify-alert-interval&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            no&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709396#M92302</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2019-03-10T10:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPS custom signature: HTTP not found</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709397#M92303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "from-service" just means the signature fires when the source port is 80.  The default, "to-service", fires only if you are connecting to a destination port of 80.  Basically the "from-service" fires on return web traffic only, which is what should happen.  Not sure why they made the default "to-service" (doesn't make much sense).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Sep 2006 20:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709397#M92303</guid>
      <dc:creator>jwalker</dc:creator>
      <dc:date>2006-09-25T20:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPS custom signature: HTTP not found</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709398#M92305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are right. I want to check traffic ("Not found") in packetes which source port is tcp/80. I think "from-service" should be used as seen in the config. (I hope default: to-service just means that the default setting is to-service, but now the setting is "from-service") &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2006 05:46:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709398#M92305</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2006-09-26T05:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPS custom signature: HTTP not found</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709399#M92307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at 6256-0 for an example of how Cisco does this.  That signature detects HTTP status code 401.  Clone and change to 404 and you're in business.  You'll want to tweak the event count and alert frequency settings of course.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2006 14:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709399#M92307</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-09-26T14:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPS custom signature: HTTP not found</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709400#M92309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much, it works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2006 15:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-http-not-found/m-p/709400#M92309</guid>
      <dc:creator>csiszerakos2</dc:creator>
      <dc:date>2006-09-26T15:37:47Z</dc:date>
    </item>
  </channel>
</rss>

