Snort mailing list archives
spp_http_decode rules
From: Ken Mencher <kenm () Buy com>
Date: Thu, 2 Aug 2001 14:55:23 -0700
I've got two of these category rules: CGI Null Byte attack & IIS Unicode attack as two of my most frequent "attacks". From what I've been able to determine, they're all totally bogus...but I can't find the .rules file where they exist... How do I disable those? Ken Mencher Network/Security Admin buy.com 949-389-2123 Cahn's Axiom: When all else fails, read the instructions.
Current thread:
- spp_http_decode rules Ken Mencher (Aug 02)
- RE: spp_http_decode rules John Berkers (Aug 03)
- RE: spp_http_decode rules John Berkers (Aug 11)
- Re: spp_http_decode rules Erek Adams (Aug 11)
- <Possible follow-ups>
- RE: spp_http_decode rules Erickson Brent W KPWA (Aug 11)
