Snort mailing list archives
Re: Snort 1.9.0 "Payload mixup".
From: Chris Green <cmg () sourcefire com>
Date: Mon, 27 Jan 2003 16:39:50 -0500
Nils Ulltveit-Moe <num () proseq no> writes:
Hi Have any of you experienced "payload mixup" with Snort 1.9.0? In our case, it is the "ICMP redirect host" rule (SID 472) that seems to display strange payload. In the three cases below, it seems that telnet or HTTP sessions are mixed with HTTP traffic from another session as the content of the ICMP message:
It should be fixed in HEAD CVS. Later, I'll work on back porting the fixes. -- Chris Green <cmg () sourcefire com> Eschew obfuscation. ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort 1.9.0 "Payload mixup". Nils Ulltveit-Moe (Jan 27)
- Re: Snort 1.9.0 "Payload mixup". Chris Green (Jan 27)