[Snort-users] IIS Unicode attack detected

Fabian Krämer fabian.kraemer at ...1573...
Wed Mar 14 04:41:58 EST 2001

Hi all,
I'm new at snorg. I've installed the current release to control our Internet
traffic. I also installed the latest rulebase. Most of the alerts snort
generates are "spp_http_decode: IIS Unicode attack detected" alerts. Those
alerts occur often if some employes do a web connection to an internet site.
I want to turn off this alert but didn't find the rule which generates this
alert. Does anybody know where I can turn off this rule?
Vitodata AG, Fabian Kraemer
Deisruetistrasse 10, CH-8472 Ohringen b. Winterthur
Telefon +41 (0)52 320 55 55, Fax +41 (0)52 320 55 66
Telefon direkt +41 (0)52 320 58 90
mailto: fabian.kraemer at ...1571... <mailto:fabian.kraemer at ...1571...> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20010314/fb7222fe/attachment.html>

More information about the Snort-users mailing list