[Snort-sigs] updated MS-RDP signature?
fixer at ...1994...
Thu Oct 30 20:19:38 EST 2003
I've noticed that the existing rule for the Remote Desktop Protocol seems to
result in an unusually high number of FPs. I'm assuming that it's because
it's based strictly on the port number as opposed to any sort of content or
anything else. Before I sit down and start attempting to hash out a new
signature, I was wondering if anyone out there had already developed one (I
hate re-inventing the wheel if I don't have to).
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs