Hi Robert, the snort rules that I made in my local.rules is a simple one to test out only.
alert tcp $EXTERNAL_NET any -> $HOME_NET 22 (msg:"SSH attempted"; sid:10001; ) Regards, Steve _________________________________________________________________ Help Splitzo Sally Before It’s Too Late! http://www.thegirlwhosplitinto5.com/
_______________________________________________ Honeywall mailing list [email protected] https://public.honeynet.org/mailman/listinfo/honeywall
