Hi Robert,

the snort rules that I made in my local.rules is a simple one to test out only.

alert tcp $EXTERNAL_NET any -> $HOME_NET 22 (msg:"SSH attempted"; sid:10001; )

Regards,
Steve

_________________________________________________________________
Help Splitzo Sally Before It’s Too Late! 
http://www.thegirlwhosplitinto5.com/
_______________________________________________
Honeywall mailing list
[email protected]
https://public.honeynet.org/mailman/listinfo/honeywall

Reply via email to