Snort mailing list archives
Re: how to disable an so_rule
From: rmkml <rmkml () yahoo fr>
Date: Fri, 30 Sep 2011 01:50:34 +0200 (CEST)
Hi, Do you have FP with this rules please? Maybe for disable, simply comment line on your dos.rules file? Don't remember related rules, look sid 17748 and 18318 (flowbits) or check with pulledpork... Regards Rmkml On Thu, 29 Sep 2011, Lawrence R. Hughes, Sr. wrote:
Hi, We are trying to disable sid:17750 a rule in the /so_rules/dos.rules hashing it does not work, so how do you these stub generated rules? Thanks, Larry
------------------------------------------------------------------------------ All the data continuously generated in your IT infrastructure contains a definitive record of customers, application performance, security threats, fraudulent activity and more. Splunk takes this data and makes sense of it. Business sense. IT sense. Common sense. http://p.sf.net/sfu/splunk-d2dcopy1
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- how to disable an so_rule Lawrence R. Hughes, Sr. (Sep 29)
- Re: how to disable an so_rule rmkml (Sep 29)
- Re: how to disable an so_rule Kevin Ross (Sep 30)
- Re: how to disable an so_rule Lawrence R. Hughes, Sr. (Sep 30)