[Snort-users] snort sees no fragmented attack

Andreas Östling andreaso at ...236...
Fri Aug 9 07:10:04 EDT 2002


On Fri, 9 Aug 2002 Holger.Woehle at ...2701... wrote:

> echo "GET /aaaaaaa/aaa/aaaaa/aaaaaaaa/aaaaaaa/bcc/bin/ps" | nc

I think this should work since you seem to have frag2 loaded...
(perhaps a very old version?)

I tried 1.9beta2 on 100 mtu ethernet and snort had no trouble with
that packet/rule (alert was generated).

/Andreas





More information about the Snort-users mailing list