Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] (snort decoder) Bad Traffic Same Src/Dst IP {trying to supress alerts from certain IP's} |
|---|---|
| Date: | Fri, 16 Sep 2005 10:42:11 -0600 |
I'm trying to suppress alerts from 2 machines where this traffic is normal. When using base to identify the SID it says the SID is 151 but when I search snort.org I can not find THIS rule. I have searched high and low to find references to this specific instance of the rule (I have already suppressed SID 527). I have run grep in my rules directory to find the rule that is creating this alert to no avail. the forum has no entries on this nor can I find anything in the archives. Where is this alert being generated from? Any help is greatly appreciated Mike
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Fwd: pcre in sid 3550, James Affeld |
|---|---|
| Next by Date: | [Snort-sigs] Emailing: 721.txt, Alan Johnson |
| Previous by Thread: | [Snort-sigs] sid: 1792 - errors, false positive and false negatives, Fabio Panigatti - Minerva spa |
| Next by Thread: | Re: [Snort-sigs] (snort decoder) Bad Traffic Same Src/Dst IP {trying to supress alerts from certain IP's}, Joel Esler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |