Actions
Bug #213
closedFail to alert on sid 2000571
Affected Versions:
Effort:
Difficulty:
Label:
Description
Suricata fails to alert on sid 2000571. Snort alerts on it.
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY AOL Webmail Message Send"; flow: to_server,established; uricontent:"/compose_frame.adp"; content:"POST"; classtype: policy-violation; reference:url,doc.emergingthreats.net/bin/view/Main/2000571; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_AOL_Webmail; sid:2000571; rev:6;)
Files
Updated by Will Metcalf over 14 years ago
Seems to fire for me will load it the test rig to see if it's consistent.
Updated by Victor Julien over 14 years ago
- Status changed from New to Closed
- Assignee changed from OISF Dev to Victor Julien
- % Done changed from 0 to 100
Should be fixed by commit 0d008c8135a76f0d22cf0fc6f9276ef93385c89a
Actions