Snort mailing list archives
Re: Looking for info re: snort rules hard coded i.e.[119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING
From: Brian <bmc () snort org>
Date: Fri, 27 Aug 2004 16:34:15 -0400
On Thu, Aug 26, 2004 at 10:37:35AM -0500, Bruce L. Donlin wrote:
Is there an easy way of getting information regarding the alerts generated by snort, but not documented in the snort signature database? Examples: [119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING
http://www.snort.org/snort-db/sid.html?sid=119:16
[119:4:1] (http_inspect) BARE BYTE UNICODE ENCODING
http://www.snort.org/snort-db/sid.html?sid=119:4
[119:2:1] (http_inspect) DOUBLE DECODING ATTACK
http://www.snort.org/snort-db/sid.html?sid=119:2 -b ------------------------------------------------------- This SF.Net email is sponsored by BEA Weblogic Workshop FREE Java Enterprise J2EE developer tools! Get your free copy of BEA WebLogic Workshop 8.1 today. http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Looking for info re: snort rules hard coded i.e.[119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING Bruce L. Donlin (Aug 27)
- Re: Looking for info re: snort rules hard coded i.e.[119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING Brian (Aug 27)