[Snort-users] Re: possible exploit

Robert T Wyatt robert.wyatt at ...3045...
Wed Feb 15 10:40:15 EST 2006


Frank Knobbe wrote:
> Your Snort didn't alert on that? Mine do all the time. It's SID 1250
> (web-misc.rules). You might want to check your config to see if this
> rule file is loaded and to ensure you don't miss other sigs too.

Patrick S. Harper wrote:
 > Old Cisco exploit.  I saw a bunch of them not too long ago.
 >
 > http://isc.sans.org/diary.php?storyid=1104

Thanks folks, I think it must have happened right when I was restarting 
snort after a rule update.

I will watch for this in the future to ensure that my setup is correct.

Thanks again,
Robert




More information about the Snort-users mailing list