Full Disclosure mailing list archives
Re: NETBIOS SMB IPC$ unicode share access
From: Michael Holstein <michael.holstein () csuohio edu>
Date: Thu, 28 Jul 2005 09:17:36 -0400
How to stop this event ie not to detect for this event. plz tell me in brief note
There are 2 major ways to do this ...1) Start Snort with the '-o' switch and then duplicate the offending signature using the 'pass' directive for the IP you want to ignore.
2) use the negation operator (!) in the rule for the IP you want to ignore. BTW: this topic dosen't belong on full-disclosure. Try the snort-users list. Regards, Michael Holstein CISSP GCIA Cleveland State University _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- NETBIOS SMB IPC$ unicode share access Ramachandrand (Jul 28)
- Re: NETBIOS SMB IPC$ unicode share access Samuel Beckett (Jul 28)
- Re: NETBIOS SMB IPC$ unicode share access J.A. Terranson (Jul 28)
- Re: NETBIOS SMB IPC$ unicode share access Michael Holstein (Jul 28)
- Re: NETBIOS SMB IPC$ unicode share access Jerome Athias (Jul 28)
- Re: NETBIOS SMB IPC$ unicode share access Michael Holstein (Jul 28)