logo       

Re: False Positive: msg#00125

security.ids.snort.sigs

Subject: Re: False Positive

At 03:59 PM 10/15/2004, nnposter@xxxxxxxxxxxxxxxxxxxxx wrote:
The rule parameters are depth:15 and offset:5 so the content clause is
restricted to payload offsets 5-19. The offending match is at offset 17
so well within the rule scope.

Doh.. you're right.. I was thinking it would be 5-15.

Looks like the original poster is being bit by having a short community string. (7 bytes).

Perhaps the depth on this rule should be changed to 10? Anyone more snmp-guruish care to comment on that impact?


-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise