Question: Question 6 What is wrong with this rule? alert tcp any any - > 1 9 2 . 1 6 8 . 0 . 0
Question
What is wrong with this rule?
alert tcp any any content: "cgibindefaultidea"; msg: "Code Red
Worm!" ; sid:;
The SID is too low and is in the reserved range.
A Snort rule cannot interpret packet content
This is not an ALERT it is an EVENT
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
