ids – How do I match any string in a list of snort contents?
If I do something like
alert tcp any any <> any any (content:”TestA”; content:”TestB”; sid:1000000; msg:”Syntax correct!”;)
then the syntax is correct, but, what I would like to do is to match either “TestA” or “TestB”. So if I g… Continue reading ids – How do I match any string in a list of snort contents?