SNORT rule with sid:0
"Wojcicki, Michal via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <DU2PR02MB768558BB4ADD10F9A5DDE16FE3689@DU2PR02MB7685.eurprd02.prod.outlook.com> |
Dear Community, I am using KEMP loadbalancer with SNORT rules applied - now only for gathering logs to adjust false-positives. Since I applied the rule it detects lots of output of type (I changed path here - just to give example): /pathchanged/123456/13_DECCC/aaa/test/somefile.aspx' - Invalid URL specification (sid:0 rev:0) Those paths and files are valid. I see that different .aspx destinations are catched by logs and this rule (sid:0 rev:0). However I cannot find its definition in community.rules - I guess sid:0 is some sort of "default" rule. I also could not find any information about sid:0. Therefore I cannot do anything, or I am missing some knowledge. Can you please tell me more about sid:0 rule? How can I exclude that from checking as all that files are valid and I cannot see this rule definition. Community rules that I use in KEMP is: https://www.snort.org/downloads -> Snort v2.9. And I changed nothing in .conf file Best Regards Michal Wojcicki _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette