[Snort-devel] Re: Snort exploits

Jason Haar Jason.Haar at ...1286...
Sun Apr 21 17:09:09 EDT 2002


On Thu, Apr 18, 2002 at 10:37:29AM -0400, Martin Roesch wrote:
> This has existed for a while and is the reason that we dumped the minfrag
> preprocessor (as a historical note).  Tiny frags do happen, but I've rarely
> see them outside of live attacks.  Then again, I don't hang on .edu networks
> very much... ;)

That used to be the case - but no more :-)

Try moving away from dedicated links to VPNs without seeing a HUGE increase
in fragments :-( [like we have]

I think we'll all find an increased interest in fragments again as more and
more companies try VPNs as a cost-saving measure.

-- 
Cheers

Jason Haar

Information Security Manager
Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417




More information about the Snort-devel mailing list