Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: Preprocessors Previous: Tuning sfPortscan   Contents


Telnet Decode

The telnet_decode preprocessor allows Snort to normalize Telnet control protocol characters from the session data. In Snort 1.9.0 and above, it accepts a list of ports to run on as arguments. Also in 1.9.0, it normalizes into a separate data buffer from the packet itself so that the raw data may be logged or examined with the rawbytes content modifier. See section [*].

By default, telnet_decode runs against traffic on ports 21, 23, 25, and 119.



Subsections

Steven Sturges 2006-12-08