[Snort-users] ACID: more alerts than I asked for in acid_stat_uaddr... :)

Andreas Hasenack andreas at ...814...
Mon Jun 25 22:54:34 EDT 2001


links-0.95 didn't work. Two things might be preventing this:
- links doesn't deal with cookies
- links didn't send a Referer tag in its request

lynx-2.8.4dev.20 worked with that page, correctly showing only one
alert. But it also didn't send a Referer tag.

Netscape-4.77 worked right as usual.

I think it's an issue with cookies, both lynx and Netscape sent cookies
back to the server (containing a PHPSESSID), but links didn't. To confirm
this, I used Konqueror and configured it to reject cookies from the
server where ACID is running. Bingo, the same problem as with links.

Em Mon, Jun 25, 2001 at 01:36:08PM -0300, Andreas Hasenack escreveu:
> I'll tcpdump some traffic later on tonight.
> 
> Em Mon, Jun 25, 2001 at 10:47:29AM +0000, roman at ...438... escreveu:
> > > Em Mon, Jun 25, 2001 at 09:50:27AM +0000, roman at ...438... escreveu:
> > > > If you are using lynx for a browser, mangled GET arguments are not surprising at all.
> > > 
> > > links, not lynx. I know that lynx doesn't work. Perhaps links should then
> > > be added to the FAQ too.
> > 
> > Your are correct.  "Links" has now been added to the "bad" browser list in the FAQ.
> > 
> > More importantly though, now that there are two independant browsers that
> > are breaking do we know why?
> > 
> > Roman




More information about the Snort-users mailing list