Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

[Snort-users] smtp rule help

0 views
Skip to first unread message

ric...@datawan.net

unread,
Nov 18, 2002, 4:44:43 PM11/18/02
to
I have been running snort for a while with Demarc as a front-end. I have
never needed to write my own rules but thought it was time to learn!
Client has a network that has Mail Relay open for all local users. I want
to log all outgoing email that is NOT from a specific domain.
"us...@somedomain.com". I tried the following and it seems to work but just
want to confirm this is right! Or the best way to do it.

alert tcp $HOME_NET any -> $EXTERNAL_NET 25 (msg:"SMTP Rule- My custom SMTP
Rule"; content:!"@somedomain.com"; depth: 22; flags: A+; nocase;
classtype:misc-activity;)

thanks in advance!

Ricardo Londoño


--------------------------------------------------------------------
mail2web - Check your email from the web at
http://mail2web.com/ .


-------------------------------------------------------
This sf.net email is sponsored by: To learn the basics of securing
your web site with SSL, click here to get a FREE TRIAL of a Thawte
Server Certificate: http://www.gothawte.com/rd524.html
_______________________________________________
Snort-users mailing list
Snort...@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list

0 new messages