Snort mailing list archives
Re: False Positive or not?
From: "AJ Butcher, Information Systems and Computing" <Alex.Butcher () bristol ac uk>
Date: Wed, 31 Mar 2004 09:19:49 +0100
--On 30 March 2004 11:56 -0600 "Cody R. Smith" <csmith () go-cypress com> wrote:
I am examining the payload of a bunch of packets and this is what it says length = 301 000 : 53 45 41 52 43 48 20 2F 41 41 41 41 41 41 41 41 SEARCH /AAAAAAAA
[etc.]
Is someone actually sending this to my webserver or is this what a browser does?
Looks to me as though someone's trying to test for a buffer overflow in your web server's handling of the SEARCH method by attempting to crash it.
Thanks Cody Smith CCNA, MCP
Best Regards, Alex. -- Alex Butcher: Security & Integrity, Personal Computer Systems Group Information Systems and Computing GPG Key ID: F9B27DC9 GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9 ------------------------------------------------------- This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux tutorial presented by Daniel Robbins, President and CEO of GenToo technologies. Learn everything from fundamentals to system administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- False Positive or not? Cody R. Smith (Mar 30)
- Re: False Positive or not? Max Valdez (Mar 30)
- Re: False Positive or not? AJ Butcher, Information Systems and Computing (Mar 31)
