[Oisf-users] How to alert for a single TCP packet?

Lucas lama2 at cin.ufpe.br
Wed Nov 27 00:02:38 UTC 2019


The rule without de http_uri modifier matches if i remove the content: 
"../" option. It makes sense since the string "../" doesn't appear in 
the packet, but why do the rule alerts when the http_uri modifier is on it?



More information about the Oisf-users mailing list