snort-sigs February 2011 archive
Main Archive Page > Month Archives  > snort-sigs archives
snort-sigs: [Snort-sigs] Question about a Snort rule

[Snort-sigs] Question about a Snort rule

From: Miso Patel <miso.patel_at_nospam>
Date: Fri Feb 25 2011 - 15:21:14 GMT
To: snort-sigs <>

My engineers are having trouble with a custom rule:

alert udp $HOME_NET any -> $EXTERNAL_NET any (msg:"iPad related HTTP
request"; content:"iPad"; http_uri; nocase; flags:S;
classtype:bad-unknown; reference:url,;
sid:18954545; rev:1;)

Any help would be appreciated. The rule does not seem to be alerting
for some reason and I think this could be a bug with Snort.


Miso, CISO

Free Software Download: Index, Search & Analyze Logs and other IT data in
Real-Time with Splunk. Collect, index and harness all the fast moving IT data
generated by your applications, servers and devices whether physical, virtual
or in the cloud. Deliver compliance at lower cost and gain new business
Snort-sigs mailing list