Snort mailing list archives
(http_inspect) NON-RFC HTTP DELIMITER issue
From: sjconsulting () optonline net
Date: Wed, 14 Jul 2004 11:21:28 -0400
I am receiving this alert and I know this alert is being generated by someone streaming "Yahoo Shoutcast" on my net...would you consider this be a false positive? Is there a way to turn this specifc inspection/alert off? I was reading through the http_inspect and I did not see where it was that allowed me to do this. I am running RH9, Snort 2.1.3. I f there is anything else that I need to post to help you folks help me, please let me know. TIA. ~SJC ------------------------------------------------------- This SF.Net email sponsored by Black Hat Briefings & Training. Attend Black Hat Briefings & Training, Las Vegas July 24-29 - digital self defense, top technical experts, no vendor pitches, unmatched networking opportunities. Visit www.blackhat.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- (http_inspect) NON-RFC HTTP DELIMITER issue sjconsulting (Jul 14)