[Snort-sigs] small dns.rules goofs

shanew at ...94... shanew at ...94...
Fri Sep 7 08:46:04 EDT 2001

I upgraded to 1.8.1 and noticed a small problem with the dns.rules.

The two DNS SPOOF rules (sid 253 and 254) have messages containing
colons.  At least on my version, when these get reported, snort cuts
them off after the colon (which makes sense given the rules syntax).

Obviously not a big deal, but something to clean up when there's time.

Public key #7BBC68D9 at            |                 Shane Williams
http://pgp.mit.edu/                |
All syllogisms contain three lines |              shanew at ...94...
Therefore this is not a syllogism  |   www.gslis.utexas.edu/~shanew

More information about the Snort-sigs mailing list