Forum Discussion

Whateve's avatar
Whateve
Icon for Bronze I rankBronze I
12 days ago

Snort Rules: Ep.5 – Fake Tech Support Popup

I have been stuck on Question 5 for a while now. 

Create a Snort rule to detect connections to this IP address from 10.1.9.101 on port 49349, then submit the token.

Does this IP refer to IP in the previous question? If so, I have tried so many different rules but one worked.

  • Write a Snort rule to detect connections between the IP address identified in the previous question on any port and IP address 10.1.9.101 on port 49349 (both directions).