[Snort-users] IIS Unicode attack

Charles-Henri Hallard ch.hallard at ...628...
Thu Jan 25 12:00:39 EST 2001


Well, does anyone know how to change the detection of IIS Unicode Attack in
spp_http_decode so that it detect only in one way ?

today i have some alerts about this but when internal hosts are surfing on
the Internet, i would like to detect this only when Internet User attack my
Web Server on port 80

any Idea ?

Also, may be a stupid question but is it possible (may be not because it's
not done) to detect this attack creating a rule ?

==============================
Charles-Henri Hallard
tél : 05 49 89 31 01
mél : ch.hallard at ...628...
==============================





More information about the Snort-users mailing list