Re: [Prelude Hybrid IDS] #185: defective squid rule in prelude-lml
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1166693068.21791.220.camel@arwen> |
Le vendredi 15 décembre 2006 à 13:59 -0500, Paul Robert Marino a écrit : > thank you the impact type was a typo on my part > I did meen to change the severity > > the reason i wanted to change the severity is because this message is > generated when squid cycles its child proccesses. In other words when a > child process has handled a predifined maximum number of transactions it > stops the child process and spawns a new one, and is also normaly followed > by > > [11323]: Squid Parent: child process 7553 started > > in the log > as such it would probably be a good idea to create a context on the rule in > the future. > > also note [11323]: is the parent process pid Hi Paul, There is the case when the Squid children is exiting because of a SIGABRT / SIGSEGV signal, in which case an higher severity alert seem to be in order. Maybe the rule should be improved to make the distinction between the two events (is a rule for a normal event like the child process exiting after a predefined maximum number of transaction necessary?). > by the way what is the prefered method of submiting a patch to a rule would > it be a diff or just submit the whole modified file The preferred method of submitting a patch is as unified diff (diff -u). Regards, -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel