[Snort-sigs] false positives for attack-response rules (and suggested fix)
bmc at ...95...
Fri Mar 19 09:03:08 EST 2004
On Fri, Mar 19, 2004 at 01:56:10PM +0100, Milani Paolo wrote:
> In some environments it can be normal to have telnet traffic in the
> network (not in very safe environments, I know). In which case these
> rules will fp a lot.
If they go off in your enviornment and its acceptable, tune them. In
most enviornments these days, these rules are just fine.
More information about the Snort-sigs