Snort mailing list archives
ssp_ssl preprocessor
From: vincent () ragosta net
Date: Tue, 15 Nov 2011 11:51:50 -0500
​Due to excessive alerts, I want to disable the "Invalid Client HELLO after Server HELLO Detected" alert (137:1) of the ssp_ssl preprocessor. Would suppressing this alert impact any other Snort rule? In other words, are there any dependencies between this preprocessor alert and any other Snort signature? Thanks, Vincent
------------------------------------------------------------------------------ RSA(R) Conference 2012 Save $700 by Nov 18 Register now http://p.sf.net/sfu/rsa-sfdev2dev1
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- ssp_ssl preprocessor vincent (Nov 15)