[Snort-users] spp_rpc_decode

Chris Green cmg at ...671...
Sat Dec 6 08:54:03 EST 2003

Paul Schmehl <pauls at ...6838...> writes:

> OK.  I guess I don't fully comprehend the process of normalization.  I
> thought I understood it to me the reassembly of fragmented packets as
> well as the conversion of "special" characters to the "standard"
> expected input (removal of unicode, etc.)  Is my understanding
> incorrect?  Does it require both sides of the conversation to
> normalize the input to those ports?

rpc_decode normalizes the RPC over TCP message segmentation format.
It's really naive and just assumes that traffic on said port is rpc

It doesn't require both sides of the conversation and it can't use it,
even if it has it.
Chris Green <cmg at ...1121...>
 "Not everyone holds these truths to be self-evident, so we've worked
                  up a proof of them as Appendix A." --  Paul Prescod

More information about the Snort-users mailing list