[Snort-users] commenting out rules?

Grant Parkinson grantp at ...1936...
Sat Jun 16 06:31:50 EDT 2001

Hi Paul,

> I am seeing a ton of "http directory traversals" appear in my snort logs
> which I have determined to be normal in my environment. So I commented out
> this rule in web-misc.rules. Then I killed and re-ran Snort. But it is still

Locate the "preprocessor http_decode:" line in your conf file and try
the -nounicode option. 


> appearing in my alert log. I tried removing the line from web-misc.rules all
> together just be sure, and it still keeps appearing in the logs as a
> possible attack.

More information about the Snort-users mailing list