Snort mailing list archives
Re: Bug in archiving with ACID 0.9.6b13+
From: "Matthew Collins" <Matthew.Collins () northernregistrars co uk>
Date: Tue, 25 Sep 2001 16:52:02 +0100
Yes, I have seen that as well. I am using v0.9.6b13 and tended to get it with Code Red alerts. Code red would produce two different alerts (IDA access and attempted CMD access). Only one of them would get archived, the other would get flagged as a duplicate and ignored. Complete guess, I've not looked at the source but is it something to do with the time stamp? It only seemed to happen on alerts that came in very quickly. I've changed my ruleset so the CMD rule checks URI not CONTENT, and that rule no longer triggers for Code red. I now only get one alert for each code red attempt, and I've not seen the duplicate warning since then.
<roman () danyliw com> 25/09/01 10:25:27 >>>
I wanted to alert the community that I am aware of a bug in the archiving functionality of ACID v0.9.6b13+ which causes the "Ignoring XXX duplicatea lerts" warning and ignores the alerts. I have also received reports of reference information not being propogated correctly when alerts are successfully archived. I am working on identifying the bug and creating the necessary patch. Roman --------------------------------------------- This message was sent using Voicenet WebMail. http://www.voicenet.com/webmail/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users **************************************************************************************** This message and any attachments are confidential to the ordinary user of the e-mail address to which it was addressed and may also be privileged. If you are not the addressee you may not copy, forward, disclose or use any part of the message or its attachments and if you have received this message in error, please notify the sender immediately by return e-mail and delete it from your system. Internet communications cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, arrive late or contain viruses. The sender therefore does not accept liability for any errors or omissions in the context of this message which arise as a result of Internet transmission. Northern Registrars Limited, Northern House, Woodsome Park, Fenay Bridge, Huddersfield. HD8 0LA. Tel: +44 (0) 1484 600900 Fax: +44 (0) 1484 600911 For more information visit our web site: http://www.northernregistrars.co.uk **************************************************************************************** _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Bug in archiving with ACID 0.9.6b13+ roman (Sep 25)
- <Possible follow-ups>
- Re: Bug in archiving with ACID 0.9.6b13+ Matthew Collins (Sep 25)