Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

I need some assistance with these snort rules. 1. Alert on any traffic with the RST flag set to the server from .128. Your message

I need some assistance with these snort rules.

image

1. Alert on any traffic with the RST flag set to the server from .128. Your message should indicate: ".128 Possible SYN Scan." 2. Alert on any FTP traffic with the SYN flag set from .128 to the victim. Message should read: ".128 attempt to FTP to victim." 3. Alert on any telnet traffic with the SYN flag set, from .128 to the victim. Message should read: ".128 attempt to telnet to victim." 4. Alert on any ssh traffic containing the keyword "SSH-2", from .128 to the server. Message should read: ".128 attempt to SSH to server." 5. Alert on any http traffic from .128 with the SYN flag set, from .128 to the server. Message should read: .128 attempt to the web server." 6. Alert on any http traffic from .128 containing "apache2.conf" sent from .128 to the server. Message should read "Found apache2.conf." 7. Alert on any packets from .128 to the victim containing "passwd". Message should read: "Found passwd." 8. Alert on any packets from .128 to the victim containing "shadow". Message should say "Found shadow" 9. Alert on any ftp traffic from the .128 to the victim that contains "jgarrett". Message should read "jgarrett over ftp". 10. Alert on any ssh traffic from .128 to the server with the FIN and ACK flags set. Message should read "F/A for SSH teardown."

Step by Step Solution

There are 3 Steps involved in it

Step: 1

Certainly I can assist you with these Snort rules Below are the Snort rules corresponding to each requirement you provided 1 Alert on any traffic with ... blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image_2

Step: 3

blur-text-image_3

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Business and Administrative Communication

Authors: Kitty o. locker, Donna s. kienzler

10th edition

77830105, 978-0077830106, 978-0073403182

More Books

Students also viewed these Computer Network questions

Question

What are ways to de-emphasize costs or donation requests?

Answered: 1 week ago

Question

When should you not apologize?

Answered: 1 week ago

Question

What are some ethical components of communication?

Answered: 1 week ago

Question

develop a psychological skills training program, and

Answered: 1 week ago