Snort mailing list archives
Re: Snort-users digest, Vol 1 #3919 - 4 msgs
From: "Aaron" <microchp () microchp org>
Date: Thu, 22 Jan 2004 08:34:22 -0800
How do I exlude attacks that to networks that I have already told snort to exclude at the command line?
(http\_inspect) BARE BYTE UNICODE ENCODINGI get this on networks I am excluding even though I am using not dst net xxx.xxx on startup.
Could I disable this globally in snort.conf? I have servers that trigger thousands of occurances but I know this is from valid traffic.
------------------------------------------------------- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See the breadth of Eclipse activity. February 3-5 in Anaheim, CA. http://www.eclipsecon.org/osdn _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: Snort-users digest, Vol 1 #3919 - 4 msgs Aaron (Jan 22)