Actions
Bug #209
closed
RR
VJ
regression v100 and git today cause two (same?) FP
Bug #209:
regression v100 and git today cause two (same?) FP
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
I have two FP with two sigs on joigned pcap file:
alert udp any any <> any 0 (msg:"BAD-TRAFFIC udp port 0 traffic"; classtype:misc-activity; sid:525; rev:9;)
alert udp any 0 -> 224.0.0.0/4 5353 (msg:"suricata fp"; classtype:bad-unknown; sid:9037079; rev:1;)
Pcap file contains only one packet with IGMP protocol.
Please Check.
Regards
Rmkml
Files
Actions