Snort mailing list archives

Re: [Snort-sigs] http_inspect


From: Jeremy Hewlett <jh () sourcefire com>
Date: Tue, 3 Aug 2004 13:57:26 -0400

On Thu, Jul 29, Esler, Joel - Contractor wrote:

   detect_anomalous_servers  config for http_inspect.  When I turn it on,
   it  works,  but  it  detects  return  HTTP  traffic as opposed to HTTP
   traffic  to  non  $HTTP_SERVERS, I am assuming that this is the probem
   with  it  right  now  and  they  are  going  to  fix it?  Or do I have
   something misconfig?

Hi Joel! Thanks for working with me on this.

For others who might be experiencing similar results, the issue is
related to not having a default entry for non-anomalous ports. We're
going to redefine anomalous servers to be specific to certain
network(s), we think this will help curb false alerts. Look for a
commit to HEAD in the Near Future (tm).





-------------------------------------------------------
This SF.Net email is sponsored by OSTG. Have you noticed the changes on
Linux.com, ITManagersJournal and NewsForge in the past few weeks? Now,
one more big change to announce. We are now OSTG- Open Source Technology
Group. Come see the changes on the new OSTG site. www.ostg.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: