[Snort-devel] Snort 1.9 cvs - ASN.1

Chris Green cmg at ...402...
Fri Apr 26 08:00:33 EDT 2002


"Smith, Donald " <Donald.Smith at ...530...> writes:

> I would love to see a few full packets.

log udp any any -> any 161

> But violation of ber encoding is how the protos stuff works. Any other tool
> that
> is based on the same concepts will work the same.
> So in many ways this rule is like the generic unicode exploit rule. It can 
> pick up NEW attacks.

Yes I know and thats why the preprocessor had started having work done
on it.  It's not done yet.
-- 
Chris Green <cmg at ...402...>
"I'm beginning to think that my router may be confused."





More information about the Snort-devel mailing list