[Snort-sigs] Sid 1748 False positives/Name Change

Scott Zawalski scott.zawalski at ...1089...
Fri Feb 13 09:36:03 EST 2004


The name of this rule "FTP command overflow attempt" should be changed 
because it only pertains to the 3CDaemon FTP Server. People who do not 
run this daemon will know they can safely disable it.


Rule: 3CDaemon FTP command overflow attempt

--
Sid: 1748

--
Summary:

--
Impact:

--
Detailed Information:

--
Affected Systems:

--
Attack Scenarios:

--
Ease of Attack:

--
False Positives: Normal use of an ftp server that is not vulnerable to 
this particular CD Overflow will have false positives when users cd to 
directories of >100 character size.

--
False Negatives:

--
Corrective Action:

--
Contributors:
-- 
Additional References:





More information about the Snort-sigs mailing list