[Snort-sigs] ssp_ssl preprocessor

vincent at ...3611... vincent at ...3611...
Tue Nov 15 11:51:50 EST 2011


​Due to excessive alerts, I want to disable the "Invalid Client HELLO after Server HELLO Detected" alert (137:1) of the ssp_ssl preprocessor.  Would suppressing this alert impact any other Snort rule?  In other words, are there any dependencies between this preprocessor alert and any other Snort signature?

Thanks,

Vincent
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20111115/0ab602cf/attachment.html>


More information about the Snort-sigs mailing list