Snort mailing list archives
what would be the effect?
From: "Onie Camara" <neil () restricted dyndns org>
Date: Fri, 5 Apr 2002 22:20:03 -0600
Will I miss a lot of attacks if I disable the preprocessor http_decode or unicode? If so, what would be those attacks?
From my experience, it tends to produce a lot of false positives, or could
it be just my snort.conf configuration? :-) What about you guys, did you disable/enable it? Comments please. I've seen a lot of people post spp_unicode but I never I really saw a helpful explanation. Thank you very much. Neil _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Portscanning from my network Steve Ochani (Apr 05)
- what would be the effect? Onie Camara (Apr 05)
- <Possible follow-ups>
- RE: Portscanning from my network Sheahan, Paul (PCLN-NW) (Apr 08)
- RE: Portscanning from my network Ryan Hill (Apr 08)
- Portscanning from my network Steve Ochani (Apr 14)