This rule detects user login not success into FTP server, but Snort cannot detect string "530 Login incorrect" in playload respone server, althought I use wireshark capture packet , I see Server have responed above string.
Could you given any recommend in this situasion?
thanks.
-- viet
Joel Esler
unread,
Nov 3, 2013, 8:29:15 AM11/3/13
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message