[Snort-users] commenting out rules?
grantp at ...1936...
Sat Jun 16 06:31:50 EDT 2001
> I am seeing a ton of "http directory traversals" appear in my snort logs
> which I have determined to be normal in my environment. So I commented out
> this rule in web-misc.rules. Then I killed and re-ran Snort. But it is still
Locate the "preprocessor http_decode:" line in your conf file and try
the -nounicode option.
> appearing in my alert log. I tried removing the line from web-misc.rules all
> together just be sure, and it still keeps appearing in the logs as a
> possible attack.
More information about the Snort-users