[Snort-users] IIS Unicode attack
ch.hallard at ...628...
Thu Jan 25 12:00:39 EST 2001
Well, does anyone know how to change the detection of IIS Unicode Attack in
spp_http_decode so that it detect only in one way ?
today i have some alerts about this but when internal hosts are surfing on
the Internet, i would like to detect this only when Internet User attack my
Web Server on port 80
any Idea ?
Also, may be a stupid question but is it possible (may be not because it's
not done) to detect this attack creating a rule ?
tél : 05 49 89 31 01
mél : ch.hallard at ...628...
More information about the Snort-users