[Snort-users] http_decode preprocessor

Alexandre Florio alexandre at ...1499...
Wed Mar 7 13:32:44 EST 2001


	How can I set up what I want to http_decode preprocessor to log? 
	I'm running snort fine, but I'm getting too much output about things that
I know that aren't attacks...

	For instance: 

-- Mar  7 08:44:15 firewall snort[26748]: spp_http_decode: CGI Null Byte attack detected: <host_on_MY_network>:1807 -> <outside_host>:80

TIA

Alexandre Florio




More information about the Snort-users mailing list