Differences

This shows you the differences between two versions of the page.

Link to this comparison view

cdci:exam [2020/05/22 20:39]
mihai.chiroiu [06. [1p] Snort2]
cdci:exam [2020/05/22 20:39] (current)
mihai.chiroiu [07. [1p] Snort3]
Line 95: Line 95:
 ==== 07. [1p] Snort3 ====  ==== 07. [1p] Snort3 ==== 
  
-Write down a snort rule that matches any ICMP traffic with the “EXAMCDCI-[A-Z]{3}“ payload encoded as Base64. Make sure an alert is generated with the following message: “EASY CDCI-EXAM”. ​+Write down a snort rule that matches any ICMP or TCP traffic with the “EXAMCDCI-[A-Z]{3}“ payload encoded as Base64. Make sure an alert is generated with the following message: “EASY CDCI-EXAM”. ​
 <​note>​ Note: “EXAMCDCI-[A-Z]{3}“ ​ is a regex and will match something like: EXAMCDCI -AZI, EXAMCDCI -YES, etc. (https://​regex101.com/​). </​note> ​ <​note>​ Note: “EXAMCDCI-[A-Z]{3}“ ​ is a regex and will match something like: EXAMCDCI -AZI, EXAMCDCI -YES, etc. (https://​regex101.com/​). </​note> ​
  
cdci/exam.txt · Last modified: 2020/05/22 20:39 by mihai.chiroiu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0