[Snort-users] Re: http_preprocessor oddity with recent CVSsnapshot

Martin Roesch roesch at ...421...
Tue Apr 3 10:23:34 EDT 2001


Sounds like it's not really turned off.  Can you turn it off and then
"grep preprocessor snort.conf" and tell us what you get?

    -Marty

JB Lallement wrote:
> 
> At 30/03/2001 10:38, Ralf Hildebrandt wrote:
> >Ok, I can confirm this now:
> >
> >a) If I DEACTIVATE http_decode, I get lots of "spp_http_decode unicode
> >    attack detected" warnings anyway.
> >
> >b) If I ACTIVATE http_decode and use -unicode, I don't get the unicode
> >    warnings anymore, but now I get:
> >
> >Mar 30 10:07:46 john snort[19596]: spp_http_decode: CGI Null byte attack
> >detected : 195.243.106.23:62116 -> 64.4.20.250:80
> 
> Hi,
> 
> did you tried to use -cginull option too ?
> 
> >Which is not as annoying, as it only occurs seldomly. But I'd really like to
> >disable the preprocessor entirely.
> >
> >--
> >ralf.hildebrandt at ...821...                            innominate AG
> >System Engineer                        Don't be afraid of what you see -
> >Diplom-Informatiker                     be afraid of what you don't see!
> >tel: +49.(0)7000.POSTFIX  fax: +49.(0)30.308806-698
> >
> 
> |---                                  ---|
>   Jean-Baptiste LALLEMENT
>   ZENI CORPORATION          http://zeni.fr
>   Tél : 0.803.003.111 Fax : 03.44.57.35.55
> |---                                  ---|
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list

--
Martin Roesch
roesch at ...421...
http://www.snort.org




More information about the Snort-users mailing list