cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1372
Views
0
Helpful
1
Replies

Uploading own snort rules

danlawrance1
Level 1
Level 1

Hi,

 

I have a requirement to upload the below snort rule to my sourcefire platform:

 

any any -> any any (msg:"Malicious SSL 01 Detected"; content:"17 03 01 00 08|"; pcre:/\x17\x03\x01\x00\x08.{4}\x04\x88\x4d\x76/"; sid:9999998;)

 

However I keep getting an error message that I cannot seem to fix, I have attached the error.

 

Snort.PNG

 

Thanks

1 Reply 1

danlawrance1
Level 1
Level 1

Copied the rule wrong onto here, the rule is:

 

alert tcp any any -> any any (msg:"Malicious SSL 01 Detected"; content:"|17 03 01 00 08|"; pcre:"/\x17\x03\x01\x00\x08.{4}\x04\x88\x4d\x76/"; rev:1; sid:9999998;)

 

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: