Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Error With Flowbit dce.bind.netware_cs |
|---|---|
| Date: | Mon, 15 Jan 2007 14:56:08 -0700 |
The latest registered users rule pack (snortrules-snapshot-CURRENT.tar.gz), released 2006-12-15, appears to contain an error. Sid 4583 that sets the flowbit: dce.bind.netware_cs has been disabled (commented out) while a number of rules that are dependant on the flowbit remain enabled by default.
Is there a reason why sid 4583 is no longer on by default? If the signature is no longer needed, then the other rules with the dce.bind.netware_cs dependancy should be disabled by default too. It is my understanding the only negative effect this error will cause is a slightly slow initial load time of snort and some unrequired memory use. This of course assumes that those rules are meant to be depreciated.
Bammkkkk
-- sguil - The Analyst Console for NSM http://sguil.sf.net
sig_4583_errors.txt
Description: Text document
------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
|---|---|
| Next by Date: | Re: [Snort-sigs] Error With Flowbit dce.bind.netware_cs, Bamm Visscher |
| Previous by Thread: | [Snort-sigs] New rule for detect ColdFusion view source with double encoding null byte, rmkml |
| Next by Thread: | Re: [Snort-sigs] Error With Flowbit dce.bind.netware_cs, Bamm Visscher |
| Indexes: | [Date] [Thread] [Top] [All Lists] |