Actions
Bug #141
closednew strange issue (no alert with two signature!)
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
ok Im continue my small suricata testing,
with this two signature below, no firing:
alert udp any any -> any 53 (msg:"dns testing"; content:"|00 00|"; depth:5; offset:13; classtype:bad-unknown; sid:9436601; rev:1;)
alert tcp any 40 -> any any (msg:"abc"; flow:to_client,established; content:"ZDZADZA0"; classtype:attempted-dos; sid:1021292; rev:1;)
{First signature is previously discussed on ticket #139}
Please this two signature with (same previous pcap on ticket #139) joigned hear.
If you comment second signature (alert tcp...), first signature alert firing, why??
Tested on suricata v0.8.2 release and git date 3 May 2010 (two version are same pb).
Regards
Rmkml
Files
Actions