|
|||||||||||
|
[Snort-sigs] 1631 CHAT AIM login false positive
From: Terence Runge <terencerunge(at)sbcglobal.net>
Date: Fri May 02 2003 - 17:57:05 EDT
C:\>netstat -an | grep 5190
Search results for: 64.12.25.151
OrgName: America Online, Inc.
I have opted to not use AOL IM and have also disabled automatic launch in the browser preferences. Still, the connection is attempted, established and maintained, resulting in a false positive. alert tcp $HOME_NET any -> $AIM_SERVERS any (msg:"CHAT AIM login"; flow:to_server,established; content:"|2a 01|"; offset:0; d epth:2; classtype:policy-violation; sid:1631; rev:4;) How could this signature be revised to not fire when a user checks mail using netscape? Changing the destination port will not do it and will only result in missing all valid and in-valid AOL IM logins.
-Terence
This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Fri May 2 18:54:12 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:27 EDT |
||||||||||
|
|||||||||||