[Snort-sigs] false positives for attack-response rules (and suggested fix)

Brian bmc at ...95...
Fri Mar 19 09:03:08 EST 2004


On Fri, Mar 19, 2004 at 01:56:10PM +0100, Milani Paolo wrote:
> In some environments it can be normal to have telnet traffic in the
> network (not in very safe environments, I know). In which case these
> rules will fp a lot.

If they go off in your enviornment and its acceptable, tune them.  In
most enviornments these days, these rules are just fine.

-brian




More information about the Snort-sigs mailing list