[Snort-sigs] False positive

Michaël Catroux michael.catroux at ...2311...
Fri Mar 12 06:50:29 EST 2004


I have a false positive with a signature.
This is an example :

[**] [1:1333:4] WEB-ATTACKS id command attempt [**]
[Classification: Web Application Attack] [Priority: 1]
03/09-15:36:41.932504 -> 172.X.X.X:1191
TCP TTL:48 TOS:0x0 ID:24248 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x338D6871  Ack: 0x9BFDB12F  Win: 0x19EC  TcpLen: 20

Thank you


More information about the Snort-sigs mailing list