logo       

Additional False Positives for rule 1:498: msg#00199

security.ids.snort.sigs

Subject: Additional False Positives for rule 1:498

I've only included the effected portion of the template:



Rule:
alert ip any any -> any any (msg:"ATTACK-RESPONSES id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:498; rev:6;)
--

Sid:
1:498

--
False Positives:
Additional false positives - receiving any text document (via http, smtp and probably other clear-text protocols as well) which contains phrases "uid=0" or "uid=root", such as when viewing/reading exploit details from Full Disclosure, PacketStorm, other security sites, etc.

R,
Coral

Attachment: cook_coral.vcf
Description: Vcard

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise