Snort mailing list archives
Ridding ourselves of flags: A+
From: "Kreimendahl, Chad J" <Chad.Kreimendahl () umb com>
Date: Tue, 29 Oct 2002 11:27:53 -0600
I noticed, after an onslaught of false positives, that there were still several rules in existence that use flags:A+ instead of the preferred flow:established. We took the liberty of modifying the rules files that still did this, and where possible added to_server or to_client. Here is a zip of all the diff's (diff -Nu).
Attachment:
RuleDiffs.tar.gz
Description: RuleDiffs.tar.gz
Current thread:
- Ridding ourselves of flags: A+ Kreimendahl, Chad J (Oct 29)