Snort mailing list archives
Sensitive_data mask_output doesn't appear to be masking output
From: James Lay <jlay () slave-tothe-box net>
Date: Thu, 09 Jan 2014 14:45:57 -0700
Here's what I got from the config
preprocessor sensitive_data: alert_threshold 25 mask_output
however the u2 file contains unmasked data. I'm using a custom rule:
alert tcp $HOME_NET any -> $EXTERNAL_NET [20,21,25]
(msg:"SENSITIVE-DATA Credit Card Numbers"; metadata:service smtp,
service ftp-data; sd_pattern:2,credit_card; classtype:sdf; sid:1001;
gid:138; rev:1;)
and the hit:
14:28:22 [138:1001:1] SENSITIVE-DATA Credit Card Numbers [**]
[Classification: Sensitive Data was Transmitted Across the Network]
[Priority: 2] {TCP} x.x.x.x:5969 -> x.x.x.x:25
Is there a way to toubleshoot this? Thanks all.
James
------------------------------------------------------------------------------
CenturyLink Cloud: The Leader in Enterprise Cloud Services.
Learn Why More Businesses Are Choosing CenturyLink Cloud For
Critical Workloads, Development Environments & Everything In Between.
Get a Quote or Start a Free Trial Today.
http://pubads.g.doubleclick.net/gampad/clk?id=119420431&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Sensitive_data mask_output doesn't appear to be masking output James Lay (Jan 09)
