What is the Correct usage of Content Modifiers in Snort rule

Viewed 130

I'm new in using Snort and I'm trying to understand Snort rules.

As I was reading Content Modifiers section in snort's manual, it is mentioned that content modifiers should be used after a content in rule options

Consider Http Uri:

As this keyword is a modifier to the previous content keyword, there must be a content in the rule before http uri is specified.

But in the latest community rules "snort3-community.rules" , there are rules that have Content modifiers before a content is specified

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS ( msg:"SERVER-WEBAPP dcboard.cgi invalid user addition attempt"; flow:to_server,established; http_uri; content:"/dcboard.cgi"; pkt_data; content:"command=register"; content:"%7cadmin"; metadata:ruleset community; service:http; reference:bugtraq,2728; reference:cve,2001-0527; reference:nessus,10583; classtype:web-application-attack; sid:817; rev:19; )

I want to know how this rule is interpreted by snort engine and also what is the correct usage of content modifiers

Thanks for your help

0 Answers
Related