Snort mailing list archives

Re: Looking for info re: snort rules hard coded i.e.[119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING


From: Brian <bmc () snort org>
Date: Fri, 27 Aug 2004 16:34:15 -0400

On Thu, Aug 26, 2004 at 10:37:35AM -0500, Bruce L. Donlin wrote:
Is there an easy way of getting information regarding the alerts
generated by snort, but not documented in the snort signature database?
 
Examples:
 [119:16:1] (http_inspect) OVERSIZE CHUNK ENCODING 

http://www.snort.org/snort-db/sid.html?sid=119:16

 [119:4:1] (http_inspect) BARE BYTE UNICODE ENCODING 

http://www.snort.org/snort-db/sid.html?sid=119:4

 [119:2:1] (http_inspect) DOUBLE DECODING ATTACK 

http://www.snort.org/snort-db/sid.html?sid=119:2

-b


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: