Using the following snort rule as a model, write a rule that would detect all the packets shown (1-6): alert tcp any any -> any 80 (msg:"LOCAL my message"; content:"my content"; nocase; sid:1000110; rev:1;) Write a rule which will match all the following: 1. 64.12.10.32:8437 -> 204.126.133.22:80 GET /admin/scripts/setup.php 2. 64.12.10.47:8435 -> 204.126.133.22:80 GET /phpAdmin/Setup.php 3. 64.12.10.2:8439 -> 204.126.133.22:80 GET /php2-1- 10/siteadmin/login.php 4. 64.12.10.18:2173 -> 204.126.133.23:80 POST /admin/scripts/setup.php 5. 64.12.11.2:2174 -> 204.126.133.23:80 GET /php2-1- 10/admin/main/setup.php 6. 64.12.11.2:2176 -> 204.126.133.23:80 GET /ADMIN/PHP/SCRIPTS/login.ph ep Note: Full points are given only if your rule is precise and doesn't generate a lots of false positives.
Using the following snort rule as a model, write a rule that would detect all the packets shown (1-6): alert tcp any any -> any 80 (msg:"LOCAL my message"; content:"my content"; nocase; sid:1000110; rev:1;) Write a rule which will match all the following: 1. 64.12.10.32:8437 -> 204.126.133.22:80 GET /admin/scripts/setup.php 2. 64.12.10.47:8435 -> 204.126.133.22:80 GET /phpAdmin/Setup.php 3. 64.12.10.2:8439 -> 204.126.133.22:80 GET /php2-1- 10/siteadmin/login.php 4. 64.12.10.18:2173 -> 204.126.133.23:80 POST /admin/scripts/setup.php 5. 64.12.11.2:2174 -> 204.126.133.23:80 GET /php2-1- 10/admin/main/setup.php 6. 64.12.11.2:2176 -> 204.126.133.23:80 GET /ADMIN/PHP/SCRIPTS/login.ph ep Note: Full points are given only if your rule is precise and doesn't generate a lots of false positives.
Database System Concepts
7th Edition
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Chapter1: Introduction
Section: Chapter Questions
Problem 1PE
Related questions
Question
![Using the following snort rule as a model, write a rule that would detect
all the packets shown (1-6):
alert tcp any any -> any 80 (msg:"LOCAL my message"; content:"my
content"; nocase; sid:1000110; rev:1;)
Write a rule which will match all the following:
1. 64.12.10.32:8437 -> 204.126.133.22:80 GET
/admin/scripts/setup.php
2. 64.12.10.47:8435 -> 204.126.133.22:80 GET /phpAdmin/Setup.php
3. 64.12.10.2:8439 -> 204.126.133.22:80 GET /php2-1-
10/siteadmin/login.php
4. 64.12.10.18:2173 -> 204.126.133.23:80 POST
/admin/scripts/setup.php
5. 64.12.11.2:2174 -> 204.126.133.23:80 GET /php2-1-
10/admin/main/setup.php
6. 64.12.11.2:2176 -> 204.126.133.23:80 GET
/ADMIN/PHP/SCRIPTS/login.ph e p
Note: Full points are given only if your rule is precise and doesn't generate
a lots of false positives.
Answer:](/v2/_next/image?url=https%3A%2F%2Fcontent.bartleby.com%2Fqna-images%2Fquestion%2F53e6c2af-4fe9-4776-a12b-71c4c9cd69aa%2Fcce13c5b-b273-4c5b-88b3-172f5e8a8dda%2Fi7n1ie_processed.png&w=3840&q=75)
Transcribed Image Text:Using the following snort rule as a model, write a rule that would detect
all the packets shown (1-6):
alert tcp any any -> any 80 (msg:"LOCAL my message"; content:"my
content"; nocase; sid:1000110; rev:1;)
Write a rule which will match all the following:
1. 64.12.10.32:8437 -> 204.126.133.22:80 GET
/admin/scripts/setup.php
2. 64.12.10.47:8435 -> 204.126.133.22:80 GET /phpAdmin/Setup.php
3. 64.12.10.2:8439 -> 204.126.133.22:80 GET /php2-1-
10/siteadmin/login.php
4. 64.12.10.18:2173 -> 204.126.133.23:80 POST
/admin/scripts/setup.php
5. 64.12.11.2:2174 -> 204.126.133.23:80 GET /php2-1-
10/admin/main/setup.php
6. 64.12.11.2:2176 -> 204.126.133.23:80 GET
/ADMIN/PHP/SCRIPTS/login.ph e p
Note: Full points are given only if your rule is precise and doesn't generate
a lots of false positives.
Answer:
Expert Solution
![](/static/compass_v2/shared-icons/check-mark.png)
This question has been solved!
Explore an expertly crafted, step-by-step solution for a thorough understanding of key concepts.
Step by step
Solved in 2 steps
![Blurred answer](/static/compass_v2/solution-images/blurred-answer.jpg)
Knowledge Booster
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.Recommended textbooks for you
![Database System Concepts](https://www.bartleby.com/isbn_cover_images/9780078022159/9780078022159_smallCoverImage.jpg)
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
![Starting Out with Python (4th Edition)](https://www.bartleby.com/isbn_cover_images/9780134444321/9780134444321_smallCoverImage.gif)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
![Digital Fundamentals (11th Edition)](https://www.bartleby.com/isbn_cover_images/9780132737968/9780132737968_smallCoverImage.gif)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
![Database System Concepts](https://www.bartleby.com/isbn_cover_images/9780078022159/9780078022159_smallCoverImage.jpg)
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
![Starting Out with Python (4th Edition)](https://www.bartleby.com/isbn_cover_images/9780134444321/9780134444321_smallCoverImage.gif)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
![Digital Fundamentals (11th Edition)](https://www.bartleby.com/isbn_cover_images/9780132737968/9780132737968_smallCoverImage.gif)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
![C How to Program (8th Edition)](https://www.bartleby.com/isbn_cover_images/9780133976892/9780133976892_smallCoverImage.gif)
C How to Program (8th Edition)
Computer Science
ISBN:
9780133976892
Author:
Paul J. Deitel, Harvey Deitel
Publisher:
PEARSON
![Database Systems: Design, Implementation, & Manag…](https://www.bartleby.com/isbn_cover_images/9781337627900/9781337627900_smallCoverImage.gif)
Database Systems: Design, Implementation, & Manag…
Computer Science
ISBN:
9781337627900
Author:
Carlos Coronel, Steven Morris
Publisher:
Cengage Learning
![Programmable Logic Controllers](https://www.bartleby.com/isbn_cover_images/9780073373843/9780073373843_smallCoverImage.gif)
Programmable Logic Controllers
Computer Science
ISBN:
9780073373843
Author:
Frank D. Petruzella
Publisher:
McGraw-Hill Education