|
|||||||||||
|
[Snort-sigs] P2P GNUTella GET causes lots of false positives
From: Shane Smith <shane(at)crownbank.com>
Date: Thu Sep 04 2003 - 15:29:01 EDT Hey Folks, I'm new to snort, so sorry if this has been covered recently. SID 1432 regarding p2p networks seems weird to me. alert tcp $HOME_NET any -> $EXTERNAL_NET !80 (msg:"P2P GNUTella GET"; flow:to_server,established; content:"GET "; offset:0; depth:4; classtype:policy-violation; sid:1432; rev:4;) If I am reading this correctly, than any packet containing "GET" headed out of my network, destined for any port other than 80 will trigger this rule. Won't this cause a false positive with every HTTP GET request to any external server with non-standard ports?
For example:
Simply hitting that URL, causes the rule to fire.
Thanks folks,
This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Thu Sep 4 16:39:04 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:35 EDT |
||||||||||
|
|||||||||||