Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Snort-sigs] P2P GNUTella GET causes lots of false positives

From: Shane Smith <shane(at)crownbank.com>
Date: Thu Sep 04 2003 - 15:29:01 EDT

Hey Folks,

I'm new to snort, so sorry if this has been covered recently. SID 1432 regarding p2p networks seems weird to me.

alert tcp $HOME_NET any -> $EXTERNAL_NET !80 (msg:"P2P GNUTella GET"; flow:to_server,established; content:"GET "; offset:0; depth:4; classtype:policy-violation; sid:1432; rev:4;)

If I am reading this correctly, than any packet containing "GET" headed out of my network, destined for any port other than 80 will trigger this rule.

Won't this cause a false positive with every HTTP GET request to any external server with non-standard ports?

For example:
http://www.nhc.rtp.nc.us:8080/

Simply hitting that URL, causes the rule to fire.

Do you need help?X

Thanks folks,
Shane



This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven.
http://thinkgeek.com/sf

Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Thu Sep 4 16:39:04 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:35 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library