[Snort-sigs] problems with .ida attempt rule in current rules and snort 1.9?

Michael Scheidell scheidell at ...249...
Sun Aug 18 15:09:01 EDT 2002


> Question:  why did this packet match the second rule and not the first?

Probably since rule two was above rule one in sig files?

better question, why bother with two rules with just a 1 char difference?

--
Michael Scheidell, CEO
SECNAP Network Security, LLC 
Sales: 866-SECNAPNET / (1-866-732-6276)
Main: 561-368-9561 / www.secnap.net
Looking for a career in Internet security?
http://www.secnap.net/employment/




More information about the Snort-sigs mailing list