Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] FP 100000122 mod_jrun |
|---|---|
| Date: | Wed, 23 Nov 2005 09:33:19 +0100 |
Le Lundi 21 Novembre 2005 10:54, Chich Thierry a écrit :
Le Lundi 21 Novembre 2005 09:52, Chich Thierry a écrit :I have a lot of FP for this rule.Some additional indications: the rule is alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg: "COMMUNITY WEB-MISC mod_jrun overflow attempt"; flow:to_server,established; content:"| 3A|"; pcre:"/^.*\x3a[^\n]{1000}/sm"; reference:bugtraq,11245; reference:cve,2004-0646; classtype:web-application-attack; sid:100000122; rev:1;) It overreact when a data flow is downloaded from the web site.
rmkml suggest to change the content by an uricontent. I think it is good idea. It cancel all the FP I had. ------------------------------------------------------- This SF.Net email is sponsored by the JBoss Inc. Get Certified Today Register for a JBoss Training Course. Free Certification Exam for All Training Attendees Through End of 2005. For more info visit: http://ads.osdn.com/?ad_idv28&alloc_id845&opÌk _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-sigs] FP on "NETBIOS SMB-DS Trans2 FIND_FIRST2 response andx overflow attempt", Brian Caswell |
|---|---|
| Next by Date: | [Snort-sigs] FP for sid 2000538, Chich Thierry |
| Previous by Thread: | Re: [Snort-sigs] FP 100000122 mod_jrun, Chich Thierry |
| Next by Thread: | [Snort-sigs] FP for 2001621 (PHP Injection Attack), Chich Thierry |
| Indexes: | [Date] [Thread] [Top] [All Lists] |