next up previous contents
Next: http_method Up: http_raw_header Previous: Format   Contents

Examples

This rule constrains the search for the pattern "EFG" to the extracted Header fields of a HTTP client request or a HTTP server response.

    alert tcp any any -> any 80 (content:"ABC"; content:"EFG"; http_raw_header;)

Note:  

The http_raw_header modifier is not allowed to be used with the rawbytes, http_header or fast_pattern modifiers for the same content.



Eugene Misnik 2013-05-08