Project

General

Profile

Actions

Bug #204

closed

Alert requiring flowbit to be set not firing.

Added by Jason Ish over 14 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Using VRT registered rules for Snort 2.8.5.3.

Sid 16435 in policy.rules requires the flowbit in sid 16425 (web-client.rules) to be set before it will alert. In the default suricata.yaml, policy.rules is loaded before web-client.rules and sid 16435 does not alert. Sid 16435 will alert if web-client.rules is listed before policy.rules in the configuration file.

Actions

Also available in: Atom PDF