Actions
Bug #149
closed
RR
VJ
FN on suricata with i(cmp)type:9
Bug #149:
FN on suricata with i(cmp)type:9
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
I have a FN with this (old) signature and joigned pcap:
alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP IRDP router advertisement"; itype:9; reference:arachnids,173; reference:bugtraq,578; reference:cve,1999-0875; classtype:misc-activity; sid:363; rev:7;)
Tested on suricata v0.8.2 and yesterday git.
Regards
Rmkml
Files
Actions