Snort mailing list archives

Safety tip for ACID users :-)


From: Jason Haar <Jason.Haar () trimble co nz>
Date: Tue, 2 Oct 2001 11:49:46 +1200

Beware! ACID and Snort can become vile enemies at the drop of a hat.

I just noticed (via snort) that we had tonnes of hits on "WEB-MISC
readme.eml attempt". Looking at it I saw that 99.99% of them came from the
ACID server itself! 

... of course the rule matches on web pages containing the string
"readme.eml"....

So, back to running ACID over https like I always should have been... :-}

-- 
Cheers

Jason Haar

Unix/Special Projects, Trimble NZ
Phone: +64 3 9635 377 Fax: +64 3 9635 417

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: