Snort mailing list archives

ssp_ssl preprocessor


From: vincent () ragosta net
Date: Tue, 15 Nov 2011 11:51:50 -0500

​Due to excessive alerts, I want to disable the "Invalid Client HELLO after Server HELLO Detected" alert (137:1) of the 
ssp_ssl preprocessor.  Would suppressing this alert impact any other Snort rule?  In other words, are there any 
dependencies between this preprocessor alert and any other Snort signature?

Thanks,

Vincent
------------------------------------------------------------------------------
RSA(R) Conference 2012
Save $700 by Nov 18
Register now
http://p.sf.net/sfu/rsa-sfdev2dev1
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: