mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

Or more generally, signatures would not work correctly for any case where the first TCP packet seen contained payload data, regardless of its TCP flags.
1 line
134 B
Text
1 line
134 B
Text
signature_match [orig_h=192.168.0.1, orig_p=80/tcp, resp_h=192.168.0.2, resp_p=80/tcp] - payload of dst-port=80/tcp contains 'passwd'
|