logo       

Re: Possible False Positive: msg#00207

security.ids.snort.sigs

Subject: Re: Possible False Positive

On 0, Brian Noel <NOELB@xxxxxxxxxx> allegedly wrote:
> FYI...
>
> We are seeing false positives with a host running the Cisco VPN client.
>

Check your $SQL_SERVERS variable first. Also, a pcap would help.

Anyone else noticing this behavior?

+-----------------------------------------------------------------+
Nigel Houghton Research Engineer Sourcefire Inc.
Vulnerability Research Team

Cat: "Forget red - let's go all the way up to brown alert!"
Kryten: "There's no such thing as a brown alert sir."
Cat: "You won't be saying that in a minute!"


-------------------------------------------------------
This Newsletter Sponsored by: Macrovision
For reliable Linux application installations, use the industry's leading
setup authoring tool, InstallShield X. Learn more and evaluate
today. http://clk.atdmt.com/MSI/go/ins0030000001msi/direct/01/


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise