snort.compatibility
来自「Firestorm NIDS是一个性能非常高的网络入侵检测系统 (NIDS)。目」· COMPATIBILITY 代码 · 共 67 行
COMPATIBILITY
67 行
Snort Compatibility (Snort 1.9.x)Rule features=============* Bidirectional rules* Forwards rules (woop-de-doo)* Backwards rules* Variables (not perfect)* Negation* IP address lists/arraysRule "features"===============* Variables not supported everywhere* Multiline rules not supported* Not all escape characters escaped (lazy snort programmers, all you need to escape is double quotes)* activate/dynamic/pass* Probably other stuff...===============================================================Keyword Plugin Comments===============================================================dns_recursive match_dns.so ***NEW***dns_iterative match_dns.so ***NEW***http_method match_http.so ***NEW***rate alerting subsystem ***NEW***burst alerting subsystem ***NEW***msg alerting subsystemdsize match_std.soip_proto match_ip.sotos match_ip.sottl match_ip.soid match_ip.so allows a rangesameip match_ip.soipoption match_ip.sofragbits match_ip.sofragoffset match_ip.so allows a rangeflags match_tcp.soseq match_tcp.so allows a rangeack match_tcp.so allows a rangeflow match_tcp.so stream/no_stream not supportedstateless match_tcp.soitype match_icmp.soicode match_icmp.soicmp_id match_icmp.so allows a rangeicmp_seq match_icmp.so allows a rangecontent match_str.souricontent match_str.so A bit lame... Will get better with full HTTP decode.offset match_str.sodepth match_str.sonocase match_str.soregex match_str.sorpc match_rpc.sosid alerting subsystemrev alerting subsystempriority alerting subsystemclasstype alerting subsystemreference NOT IMPLEMENTED (pointless, keep them in a database)tag NOT IMPLEMENTED (pretty easy)content-list NOT IMPLEMENTED (easy, but hacky)logto could be useful?resp not likelyreact not likely
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?