[Snort-users] how to write rule to match content in http responce gzip encoding?
411 views
Skip to first unread message
Mitesh Jadia
unread,
Dec 13, 2012, 12:57:44 PM12/13/12
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Hello,
I am writing one rule like
content:"ABC";nocase;msg:....
http response is in gzip encoding and I have enabled ZLIB while configuring snort. Also http_inspect preprocessor configuration is set to extended_response_inspection. But this rule is not getting matched.
Please show me proper way.
Regards,
Mitesh
waldo kitty
unread,
Dec 13, 2012, 1:13:44 PM12/13/12
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
post the rule that you have as it is... you may be close or you may be a world
away... we cannot tell without seeing the rule...
there are several ways to do things and one answer is not always /the/ only
answer...
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
On 2012-12-13 10:57, Mitesh Jadia wrote: > Hello, > > I am writing one rule like > content:"ABC";nocase;msg:.... > > http response is in gzip encoding and I have enabled ZLIB while > configuring snort. Also http_inspect preprocessor configuration is > set > to extended_response_inspection. But this rule is not getting > matched. > > > Please show me proper way. >
> Regards, > Mitesh
Make sure you enable inspect_gzip in your http_inspect. You'll also need the file_data; in order to normalize the content.