Snort mailing list archives

Re: how to disable an so_rule


From: rmkml <rmkml () yahoo fr>
Date: Fri, 30 Sep 2011 01:50:34 +0200 (CEST)

Hi,
Do you have FP with this rules please?
Maybe for disable, simply comment line on your dos.rules file?
Don't remember related rules, look sid 17748 and 18318 (flowbits) or check with pulledpork...
Regards
Rmkml


On Thu, 29 Sep 2011, Lawrence R. Hughes, Sr. wrote:

Hi,
We are trying to disable sid:17750 a rule in the /so_rules/dos.rules   hashing it does not work, so how do you these 
stub generated rules?
Thanks,
Larry
------------------------------------------------------------------------------
All the data continuously generated in your IT infrastructure contains a
definitive record of customers, application performance, security
threats, fraudulent activity and more. Splunk takes this data and makes
sense of it. Business sense. IT sense. Common sense.
http://p.sf.net/sfu/splunk-d2dcopy1
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: