|
|
@@ -7,20 +7,32 @@ |
|
|
|
#
|
|
|
|
|
|
|
|
#snf4sa.cf
|
|
|
|
|
|
|
|
####################################################################
|
|
|
|
# Modify the following to suit your installation.
|
|
|
|
####################################################################
|
|
|
|
|
|
|
|
describe SNF4SA Message Sniffer
|
|
|
|
|
|
|
|
# Default configuration.
|
|
|
|
GBUdb_max_weight 3.0
|
|
|
|
snf_result 1 sa_score -5.0 short_circuit_no
|
|
|
|
snf_result 20 sa_score 6.0 short_circuit_yes
|
|
|
|
snf_result 40 sa_score 2.5 short_circuit_no
|
|
|
|
snf_result 47-62 sa_score 4.0 short_circuit_no
|
|
|
|
snf_result 63 sa_score 3.5 short_circuit_no
|
|
|
|
|
|
|
|
|
|
|
|
####################################################################
|
|
|
|
# Do not modify anything below this line.
|
|
|
|
####################################################################
|
|
|
|
|
|
|
|
# Name of plugin and rule.
|
|
|
|
loadplugin Snf4sa snf4sa.pm
|
|
|
|
full SNF4SA eval:snf4sa_sacheck()
|
|
|
|
describe SNF4SA Message Sniffer
|
|
|
|
|
|
|
|
# Header line containing the results from SNFServer.
|
|
|
|
add_header all SNF-Result _SNFRESULTTAG_
|
|
|
|
add_header all MessageSniffer-Scan-Result _SNFMESSAGESNIFFERSCANRESULT_
|
|
|
|
add_header all MessageSniffer-Rules _SNFMESSAGESNIFFERRULES_
|
|
|
|
add_header all GBUdb-Analysis _SNFGBUDBANALYSIS_
|
|
|
|
|
|
|
|
# Test lines.
|
|
|
|
GBUdb_max_weight 3.0
|
|
|
|
snf_result 1 sa_score -5.0 short_circuit_no
|
|
|
|
snf_result 20 sa_score 6.0 short_circuit_yes
|
|
|
|
snf_result 40 sa_score 5.0 short_circuit_no
|
|
|
|
snf_result 47-62 sa_score 4.0 short_circuit_no
|
|
|
|
snf_result 63 sa_score 2.5 short_circuit_no
|