Snort mailing list archives

Re: http_inpect appears to mangle contents


From: Andreas Östling <andreaso () it su se>
Date: Fri, 15 Oct 2004 09:40:28 +0200


On Thursday 14 October 2004 23:02, Giles, David C. wrote:
   If I comment out the above http_inspect lines in snort.conf then
snort detects my test page otherwise it does not.

   The test server is an Apache 2.0.45 server and the test page is:

<html><body>
A page to trigger a snort alarm<br>
This is a flat page with "My SnORt test" for testing snort.
</body></html>

Perhaps you need to adjust flow_depth (see doc/README.http_inspect).
As a test, add "flow_depth 0" to your http_inspect_server statement and see if 
it helps:

preprocessor http_inspect_server: server default \
    profile all ports { 80 8080 8180 } oversize_dir_length 500 flow_depth 0

This can impact performance though.

/Andreas


-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: