On  0, Russell Fulton <r.fulton at ...575...> allegedly wrote:
> --
> False Positives:  This rule will trigger on *any* occurrence of "shadow"
> in the ftp control stream. I suggest requiring a RETR before the
> "shadow" and this will prevent FPs on domain names and usernames etc.

Check your rule, here is the existing Snort rule...

alert tcp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"FTP shadow retrieval
attempt"; flow:to_server,established; content:"RETR"; nocase;
content:"shadow"; classtype:suspicious-filename-detect; sid:1928; rev:3;)

