[Snort-sigs] rule 1882 broken
lists at ...1802...
Fri Aug 22 09:17:33 EDT 2003
it seems that rule 1882 is broken in CVS.
i had no problem with it until i changed to snortcenter and tried to
activate the rules with a reload after an update and push of the config.
is this a snortcenter problem, or really a problem in the sid ?
attack-responses.rules:#alert ip $HOME_NET any -> $EXTERNAL_NET any \
(msg:"ATTACK-RESPONSES id check returned userid"; content:"uid="; \
byte_test:5,<,65537,0,relative,string; content:" gid="; distance:0; \
within:15; byte_test:5,<,65537,0,relative,string; classtype:bad-unknown; \
spamtrap: boppie at ...1802...
personal: bob at ...1802...
More information about the Snort-sigs