|
Re: reporting false positives...: msg#00161security.ids.snort.sigs
Yup that order is pretty much on the money, also make sure you include the rule SID and REV, and make sure your HOME_NET and EXTERNAL_NET variables aren't set to "any". In some cases it also doesn't hurt to include the version of snort your running. As for when to resort to getting full dumps, if you can't do it all the time, is when the protocol has extra context in the stream. Good examples of this are DCERPC and SMB, as packets sent previously in the stream influence what things mean latter on in the stream. Cheers, -matt Russell Fulton wrote: Thanks Matt & Janson for responses: This has confirmed what I had ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Rules utilisation: 00161, Chich Thierry |
|---|---|
| Next by Date: | Re: Rules utilisation: 00161, Matt Jonkman |
| Previous by Thread: | Re: reporting false positives...i: 00161, Jason |
| Next by Thread: | FP for NETBIOS SMB-DS DCERPC NTLMSSP asn1 overflow attempt: sid 2383: 00161, Russell Fulton |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |