[Snort-users] commenting out rules?

Sheahan, Paul (PCLN-NW) Paul.Sheahan at ...2218...
Sat Jun 16 03:08:21 EDT 2001


I am seeing a ton of "http directory traversals" appear in my snort logs
which I have determined to be normal in my environment. So I commented out
this rule in web-misc.rules. Then I killed and re-ran Snort. But it is still
appearing in my alert log. I tried removing the line from web-misc.rules all
together just be sure, and it still keeps appearing in the logs as a
possible attack.

What am I missing? How do I get Snort to stop checking for this attack and
others like it?

Thanks!
Paul




More information about the Snort-users mailing list