[Snort-sigs] DDOS false positive

Bryan Irvine bryan.irvine at ...1441...
Fri Dec 26 09:51:01 EST 2003


I need help trying to troubleshoot a suspected false positive with the
DDOS mstream client handler rule.

According to the signature db, there aren't any known false positives,
but I seem to be getting a bunch when people go the autoconnect (now
autotrader) website.

What should I look for to troubleshoot and report this?

--Bryan





More information about the Snort-sigs mailing list