Snort mailing list archives
var HTTP_PORTS and new rules
From: Erik Nyman <m9520 () abc se>
Date: Tue, 18 Nov 2003 13:06:55 +0100 (MET)
Hi! I have installed snort on RH 9 and it's up and running just fine. I have two basic questions. 1. I got a lot of FP on 8080, and I can't figure it out how to fix it. We have internal webservers that run on port 80, and mainly all other traffic goes through a proxy on port 8080. You can't set [80,8080] like you do for networks, just a range like 80:8080. 2. How often should I download new rules? Because I edit in the rules to get rid of a lot of FP, but maybe there is a better way to do that. Is there a possibillity to have the exclusions in a separate file? ------------------ Erik Nyman eny () abc se ------------------------------------------------------- This SF. Net email is sponsored by: GoToMyPC GoToMyPC is the fast, easy and secure way to access your computer from any Web browser or wireless device. Click here to Try it Free! https://www.gotomypc.com/tr/OSDN/AW/Q4_2003/t/g22lp?Target=mm/g22lp.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- var HTTP_PORTS and new rules Erik Nyman (Nov 18)