Snort mailing list archives

Not feeling the LOVE


From: "Ben Keepper" <bkeepper () Paladinss com>
Date: Mon, 4 Mar 2002 10:56:11 -0800

I have posted several times all over webdom and have not recieved a
single reply to this question:
 
"I posted this to the snort users list. No replies. I don't think it is
a stupid question and it is not covered in the documentation. 
I am getting a lot of spp_unidecode (mostly CGI null byte attack)false
postives originating from my firewall NAT address going ONLY to specific
web sites (ingrammicro and compaq to be specific).
How can I eliminate these false positives. Obviously normal rule
modifications won't work because this is a preprocessor.
ANY help would be appreciated."
 
If everybody is ignoring because this is covered in the documentation,
please be helpful and point me to spot.
 
I can't believe I am the only having this issue.
 
Once again, any help (or thoughts would be appreciated),
 
Thanks,
 
Ben
Jz+���ɚ�X��X��)��۬z�%��l���q����zѨ��a��.����z���m��좻����r��zm����+-��.�ǟ�����+-��b�ا~�잊��ǫ�)��۬z�%��Z��b��m����
 z�+k   ^��&������w�+-

Current thread: