Re: [Prelude Hybrid IDS] #185: defective squid rule in prelude-lml

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <1166693068.21791.220.camel@arwen>
Le vendredi 15 décembre 2006 à 13:59 -0500, Paul Robert Marino a écrit :
> thank you the impact type was a typo on my part
> I did meen to change the severity
> 
> the reason i wanted to change the severity is because this message  is
> generated when squid cycles its child proccesses. In other words when a
> child process has handled a predifined maximum number of transactions it
> stops the child process and spawns a new one, and is also normaly followed
> by
> 
> [11323]: Squid Parent: child process 7553 started
> 
> in the log
> as such it would probably be a good idea to create a context on the rule in
> the future.
> 
> also note [11323]: is the parent process pid

Hi Paul,

There is the case when the Squid children is exiting because of a
SIGABRT / SIGSEGV signal, in which case an higher severity alert seem to
be in order. 

Maybe the rule should be improved to make the distinction between the
two events (is a rule for a normal event like the child process exiting
after a predefined maximum number of transaction necessary?).

> by the way what is the prefered method of submiting a patch to a rule would
> it be a diff or just submit the whole modified file

The preferred method of submitting a patch is as unified diff (diff -u).


Regards,

-- 
Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                  Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com

_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.