Snort rules with content
问题 This will generate an alert: alert tcp any any <> any any (msg:"Test_A"; sid:3000001; rev:1;) This will not: alert tcp any any <> any any (msg:"Test_B"; content:"badurl.com"; http_header; sid:3000002; rev:1;) I have tried: fast_pattern:only; metadata:service http; nocase; http_header; and others. I cannot get it to work at this generic level. Any ideas why the content attribute does not work? The packet has a URL. Updated from the comments 0000 9c d2 4b 7d 96 60 3c 15 c2 dc 48 fa 08 00 45 00