[Snort-users] Question on SID 18358

Lay, James james.lay at ...15009...
Fri Apr 8 14:36:42 EDT 2011


The user agent applies to the client request and is not associated with
a particular URL.  If the application requesting the URL declares itself
as User-Agent: NSIS_NETLOAD", then this rule will fire.





Thanks Matt....guess I was originally wondering if this was malicious or
not...this link may help though:


My guess is that this the appusage gets reported on install maybe, since
I've never seen this fire until yesterday, and haven't seen it since.
Very strange.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20110408/fb142e80/attachment.html>

More information about the Snort-users mailing list