|
Re: reporting false positives...: msg#00148security.ids.snort.sigs
The difference between 2 and 3 is that a pcap is easier to work with and verify. An ascii dump requires that a packet be crafted and then added to a session to run through snort where a pcap can be used natively. It is easy to do a snort -dve -r pcap.file but more difficult to recreate the pcap from an ascii dump. Nemesis and netdude leave plenty of opportunity to oops when going from ascii to pcap. Russell Fulton wrote: Thanks Matt & Janson for responses: This has confirmed what I had ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Colin Slevin/TRANSWARE/IE is out of the office.: 00148, Jeff Nathan |
|---|---|
| Next by Date: | Re: FP for NETBIOS SMB-DS DCERPC NTLMSSP asn1 overflow attempt: sid 2383: 00148, Jason |
| Previous by Thread: | Re: reporting false positives...i: 00148, Matt Jonkman |
| Next by Thread: | Re: reporting false positives...: 00148, Matthew Watchinski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |