Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] (snort decoder) Bad Traffic Same Src/Dst IP {trying to

Subject: Re: [Snort-sigs] (snort decoder) Bad Traffic Same Src/Dst IP {trying to supress alerts from certain IP's}
Date: Fri, 23 Sep 2005 08:42:53 -0400
This alert is being generated from the snort_decoder itself. See the config directives for instructions on how to shut these off (Snort manual, page 16/17ish..)

Joel Esler
SOURCEfire


On Sep 16, 2005, at 12:42 PM, Mike Kelley wrote:

I'm trying to suppress alerts from 2 machines where this traffic is normal. When using base to identify the SID it says the SID is 151 but when I search snort.org I can not find THIS rule. I have searched high and low to find references to this specific instance of the rule (I have already suppressed SID 527).

I have run grep in my rules directory to find the rule that is creating this alert to no avail. the forum has no entries on this nor can I find anything in the archives. Where is this alert being generated from?

Any help is greatly appreciated

Mike







<Prev in Thread] Current Thread [Next in Thread>