GeniusWoo / idshwk1

a snort rule about tcp packet detection

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

idshwk1

detect a tcp packet with

• Destination Port at 8080, TCPFLAG ACK set, a string “hostip”

• in payload [10th byte-20th byte]

• alert message “TEST ALERT”

About

a snort rule about tcp packet detection