[Snort-devel] Snort reports 403 error in reverse
Hugo van der Kooij
hvdkooij at ...372...
Mon Apr 16 11:58:16 EDT 2001
It seems the current rules report any blocked access to a webserver (HTTP
code 403) the other way around. I know it is detected by the response of
the webserver only but it would be nice to exchange source and destination
addresses for the rapports.
I noticed it when reporting the alerts with snortsnarf.
Alle email aan mij verzonden is gebonden aan de regels beschreven op
All email send to me is bound to the rules described on my homepage.
Hugo van der Kooij; Oranje Nassaustraat 16; 3155 VJ Maasland
hvdkooij at ...372... http://hvdkooij.xs4all.nl/
Don't meddle in the affairs of sysadmins,
for they are subtle and quick to anger.
More information about the Snort-devel