Snort mailing list archives
Re: 1:17239 False Positive
From: Joel Esler <jesler () sourcefire com>
Date: Tue, 12 Oct 2010 15:42:47 -0400
Right, that's the general rule of thumb, however, this rule was updated in today's rulepack. Joel On Oct 12, 2010, at 12:21 PM, Christopher A. Libby wrote:
My initial guess would be disable this rule if you aren't using the product - the non-email port FP's are the only ones that really concern me. - Chris Christopher A. Libby Network & Security Administrator IT Department - Phone 207-760-2508 -----Original Message----- From: James Lay [mailto:jlay () slave-tothe-box net] Sent: Tuesday, October 12, 2010 8:43 AM To: Snort Subject: Re: [Snort-users] 1:17239 False Positive Count me in here too...I saw a lot of these yesterday on port 25. On 10/12/10 6:32 AM, "Christopher A. Libby" <clibby () mainepublicservice com> wrote:1:17239 "IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt" is giving me a false positive on SQL Server backup traffic. Could this rule be successfully limited to known IMAP ports? -------------------------------------------------------------------------- ---- Beautiful is writing same markup. Internet Explorer 9 supports standards for HTML5, CSS3, SVG 1.1, ECMAScript5, and DOM L2 & L3. Spend less time writing and rewriting code and more time creating great experiences on the web. Be a part of the beta today. http://p.sf.net/sfu/beautyoftheweb _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users------------------------------------------------------------------------------ Beautiful is writing same markup. Internet Explorer 9 supports standards for HTML5, CSS3, SVG 1.1, ECMAScript5, and DOM L2 & L3. Spend less time writing and rewriting code and more time creating great experiences on the web. Be a part of the beta today. http://p.sf.net/sfu/beautyoftheweb _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------------------------------ Beautiful is writing same markup. Internet Explorer 9 supports standards for HTML5, CSS3, SVG 1.1, ECMAScript5, and DOM L2 & L3. Spend less time writing and rewriting code and more time creating great experiences on the web. Be a part of the beta today. http://p.sf.net/sfu/beautyoftheweb _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
-- Joel Esler 302-223-5974 ------------------------------------------------------------------------------ Beautiful is writing same markup. Internet Explorer 9 supports standards for HTML5, CSS3, SVG 1.1, ECMAScript5, and DOM L2 & L3. Spend less time writing and rewriting code and more time creating great experiences on the web. Be a part of the beta today. http://p.sf.net/sfu/beautyoftheweb _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- 1:17239 False Positive Christopher A. Libby (Oct 12)
- Re: 1:17239 False Positive James Lay (Oct 12)
- Re: 1:17239 False Positive Christopher A. Libby (Oct 12)
- Re: 1:17239 False Positive Joel Esler (Oct 12)
- Re: 1:17239 False Positive waldo kitty (Oct 12)
- Re: 1:17239 False Positive Joel Esler (Oct 12)
- Re: 1:17239 False Positive Christopher A. Libby (Oct 12)
- Re: 1:17239 False Positive James Lay (Oct 12)