cmg at ...671...
Sat Dec 6 08:54:03 EST 2003
Paul Schmehl <pauls at ...6838...> writes:
> OK. I guess I don't fully comprehend the process of normalization. I
> thought I understood it to me the reassembly of fragmented packets as
> well as the conversion of "special" characters to the "standard"
> expected input (removal of unicode, etc.) Is my understanding
> incorrect? Does it require both sides of the conversation to
> normalize the input to those ports?
rpc_decode normalizes the RPC over TCP message segmentation format.
It's really naive and just assumes that traffic on said port is rpc
It doesn't require both sides of the conversation and it can't use it,
even if it has it.
Chris Green <cmg at ...1121...>
"Not everyone holds these truths to be self-evident, so we've worked
up a proof of them as Appendix A." -- Paul Prescod
More information about the Snort-users