How can I set a rule for checking also and hex-string like linux iptables?
I want to write a rule to cacth this package
-m string --algo kmp --hex-string "|55ffffffff|"
Really thanks for your help.ip firewall layer7-protocol add name=match-55ffffff regexp="\\x55\\xff\\xff\\xff"
packet going with other hex how can I wildcard it?
ffffffff55872ede29
I don't understand the question. You have provided three regular expressions, none of which matches a superset of what any of the remaining two matches. The last one matches four 0xff bytes in a row but they must be preceded by 0x55 which is not the case for the other two.Is it true 3 string? Lastone is for wildcard for the rest.
\\xff\\xff\\xff\\xff\\x54\\x53\\x6f\\x75\\x72\\x63\\x65\\x20\\x45\\x6e\\x67\\x69\\x6e\\x65\\x20\\x51\\x75\\x65\\x72\\x79.*
\\xff\\xff\\xff\\xff\\x67\\x65\\x74\\x63\\x68\\x61\\x6c\\x6c\\x65\\x6e\\x67\\x65\\x20
\\x55\\xff\\xff\\xff\\xff.*