Snort mailing list archives

Ridding ourselves of flags: A+


From: "Kreimendahl, Chad J" <Chad.Kreimendahl () umb com>
Date: Tue, 29 Oct 2002 11:27:53 -0600


I noticed, after an onslaught of false positives, that there were still
several rules in existence that use flags:A+ instead of the preferred
flow:established.

We took the liberty of modifying the rules files that still did this,
and where possible added to_server or to_client.  Here is a zip of all
the diff's (diff -Nu).

Attachment: RuleDiffs.tar.gz
Description: RuleDiffs.tar.gz


Current thread: