Project

General

Profile

Actions

Feature #609

open

Active Response in inline mode (like react in snort 2.9+)

Added by Dmitry Vlasov about 12 years ago. Updated over 5 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
high
Difficulty:
medium
Label:

Description

Rule option keyword that enables sending an HTML page on a session and then resetting it

Example rule:
drop tcp any any -> any 80 (msg:"http://bad.url"; content:"Host: bad.url"; react: msg; sid:283; rev:1;)

http://manual.snort.org/node26.html#SECTION003114000000000000000

Actions

Also available in: Atom PDF