[Snort-sigs] False positive for 2460
matt at ...2436...
Thu Jul 1 11:18:04 EDT 2004
# This is a template for submitting snort signature descriptions to
# the snort.org website
# Ensure that your descriptions are your own
# and not the work of others. References in the rules themselves
# should be used for linking to other's work.
# If you are unsure of some part of a rule, use that as a commentary
# and someone else perhaps will be able to fix it.
CHAT Yahoo IM webcam request
False positive. Audio chat messages incoming set this off. Remedying
this may be as simple as renaming the rule to "CHAT Yahoo IM webcam or
Audio messages are being deemed webcam connections.
A user that was participating in a text chat session that had audio
messages being sent was triggering this rule.
Ease of Attack:
Audio chat traffic will also trigger this rule.
Rename rule, or look further into the protocol and see if a packet
containing <RVWCFG> is specific to only an audio session.
More information about the Snort-sigs