[Snort-users] Snort 1.9.0 "Payload mixup".

Chris Green cmg at ...1935...
Mon Jan 27 13:43:01 EST 2003

Nils Ulltveit-Moe <num at ...8105...> writes:

> Hi
> Have any of you experienced "payload mixup" with Snort 1.9.0? In our
> case, it is the "ICMP redirect host" rule (SID 472) that seems to
> display strange payload. In the three cases below, it seems that
> telnet or HTTP sessions are mixed with HTTP traffic from another
> session as the content of the ICMP message:

It should be fixed in HEAD CVS.  Later, I'll work on back porting the
Chris Green <cmg at ...1935...>
Eschew obfuscation.

More information about the Snort-users mailing list