[Snort-sigs] small dns.rules goofs

Brian bmc at ...95...
Fri Sep 7 17:11:01 EDT 2001


According to shanew at ...94...:
> I upgraded to 1.8.1 and noticed a small problem with the dns.rules.
> 
> The two DNS SPOOF rules (sid 253 and 254) have messages containing
> colons.  At least on my version, when these get reported, snort cuts
> them off after the colon (which makes sense given the rules syntax).
> 
> Obviously not a big deal, but something to clean up when there's time.

Thanks for the catch.  Fixed in CVS.

-brian




More information about the Snort-sigs mailing list