next up previous contents
Next: metadata Up: priority Previous: Format   Contents

Examples

    alert tcp any any -> any 80 (msg:"WEB-MISC phf attempt"; flags:A+; \
        content:"/cgi-bin/phf"; priority:10;)

    alert tcp any any -> any 80 (msg:"EXPLOIT ntpdx overflow"; \ 
        dsize:>128; classtype:attempted-admin; priority:10 );



Eugene Misnik 2013-05-08