[Snort-sigs] Sid 1748 False positives/Name Change

Brian bmc at ...95...
Fri Feb 13 17:00:01 EST 2004


On Fri, Feb 13, 2004 at 09:33:40AM -0800, Scott Zawalski wrote:
> The name of this rule "FTP command overflow attempt" should be changed 
> because it only pertains to the 3CDaemon FTP Server. People who do not 
> run this daemon will know they can safely disable it.

Uh, no.  It doesn't just refer to that server.  It refers to all sorts
of servers.  Thats just ONE of the many vulnerabilities that can be
picked up by that rule.

Brian




More information about the Snort-sigs mailing list