[Snort-sigs] rule 1882 broken
Hi,
it seems that rule 1882 is broken in CVS.
i had no problem with it until i changed to snortcenter and tried to
activate the rules with a reload after an update and push of the config.
is this a snortcenter problem, or really a problem in the sid ?
attack-responses.rules:#alert ip $HOME_NET any -> $EXTERNAL_NET any \
(msg:"ATTACK-RESPONSES id check returned userid"; content:"uid="; \
byte_test:5,<,65537,0,relative,string; content:" gid="; distance:0; \
within:15; byte_test:5,<,65537,0,relative,string; classtype:bad-unknown; \
sid:1882; rev:9;)
--
Bob Tito
spamtrap: boppie@magicfingers.org
personal: bob@magicfingers.org
-------------------------------------------------------
This SF.net email is sponsored by: VM Ware
With VMware you can run multiple operating systems on a single machine.
WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines
at the same time. Free trial click here:
http://www.vmware.com/wl/offer/358/0
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
Received on Fri Aug 22 12:34:14 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:08:34 EDT
|