Snort mailing list archives

Re: Problems with links in ACID


From: "AJ Butcher, Information Systems and Computing" <Alex.Butcher () bristol ac uk>
Date: Wed, 10 Mar 2004 08:55:05 +0000



--On 09 March 2004 18:17 -0300 "Luis Claudio R. da Silveira" <lsilveira () tse gov br> wrote:

Hello Snorters,

I have a ACID console that shows a list of alerts from a snort sensor. For
security reasons, this network (acid with sensor) is completely isolated
from my real net where I could search for alerts in snort database
(www.snort.org/snort-db/).

Shouldn't make any difference, as long as the browser you're using to access your ACID console can reach www.snort.org.

But a there's a problem between ACID alert sid
numbers and Snort sid numbers, i.e, I can't get any snort alert
description in snort-db using alert sids generated by ACID :
Example :

My ACID console reports :
<snort> NON-RFC HTTP DELIMITER - link
http://www.snort.org/snort-db/sid.html?sid=13

When I try to get this sid (13) using this link in snort DB, I don't get
any response.

Does anyone have some clue or help to resolve this problem?

You should get a "Sorry, no sid" page. Some signatures don't have corresponding entries in the snort-db. Feel free to visit <http://www.snort.org/cgi-bin/needed.cgi> and help fill in some of the missing entries.

Thanks in advance,
Luis Claudio R da Silveira

Best Regards,
Alex.
--
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9




-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: