[Snort-sigs] Re: Question about bleeding Netsky rule?

James Riden j.riden at ...1766...
Sat Jan 15 16:12:00 EST 2005

Matt Jonkman <matt at ...2436...> writes:

> You're correct, it should be tcp. Surprised snort hasn't complained
> about that one. Thanks for pointing it out.
> Fixed and posted. Thanks

There seem to be a few other 'alert icmp' instead of 'alert tcp' - all
netsquid imported rules it seems. I think I sent the details in email,
but it's fairly obvious which ones are wrong. Let me know if you want
a list.

James Riden / j.riden at ...1766... / Systems Security Engineer
Information Technology Services, Massey University, NZ.
GPG public key available at: http://www.massey.ac.nz/~jriden/

More information about the Snort-sigs mailing list