[Snort-sigs] Rules sid:2000344 and following (IRC).

Matthew Jonkman matt at ...2436...
Mon Aug 16 06:35:18 EDT 2004

I agree with you on the 3600 second tag. That might be excessive. I've 
changed them all to 300.

Not sure what you're saying on point number 2. Can you elaborate?



Chich Thierry wrote:
> The bleeding edge rules sid:2000344 and following, that are looking for
> IRC traffic on non standard-port give me huge trace.
> First of all, the session time (3600 seconds) is too long. Some people
> use IRC in order to transmit divx files or warez.
> Secondly, some rules announce that they  track activity on non-std port
> but there is nothing in the reule that check the port. In my database,
> I have capture 100000 packets of a chat session, and I truly doubt that 
> the user
> has sent a real message in these 100000 packets.
> Thierry Chich
> -------------------------------------------------------
> SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
> 100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
> Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
> http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs

More information about the Snort-sigs mailing list