[Snort-devel] Snort reports 403 error in reverse

Hugo van der Kooij hvdkooij at ...372...
Mon Apr 16 11:58:16 EDT 2001


It seems the current rules report any blocked access to a webserver (HTTP
code 403) the other way around. I know it is detected by the response of
the webserver only but it would be nice to exchange source and destination
addresses for the rapports.

I noticed it when reporting the alerts with snortsnarf.


Alle email aan mij verzonden is gebonden aan de regels beschreven op
mijn homepage.
All email send to me is bound to the rules described on my homepage.

    Hugo van der Kooij; Oranje Nassaustraat 16; 3155 VJ  Maasland
    hvdkooij at ...372...		http://hvdkooij.xs4all.nl/

	    Don't meddle in the affairs of sysadmins,
	    for they are subtle and quick to anger.

More information about the Snort-devel mailing list