[Snort-users] Re: possible exploit
Robert T Wyatt
robert.wyatt at ...3045...
Wed Feb 15 10:40:15 EST 2006
Frank Knobbe wrote:
> Your Snort didn't alert on that? Mine do all the time. It's SID 1250
> (web-misc.rules). You might want to check your config to see if this
> rule file is loaded and to ensure you don't miss other sigs too.
Patrick S. Harper wrote:
> Old Cisco exploit. I saw a bunch of them not too long ago.
Thanks folks, I think it must have happened right when I was restarting
snort after a rule update.
I will watch for this in the future to ensure that my setup is correct.
More information about the Snort-users