Re: how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]"
"Vitalii Serhiiovych Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]> Tue, 29 Aug 2023 08:45:28 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <MW4PR11MB82909426E832335E1029083EDBE7A@MW4PR11MB8290.namprd11.prod.outlook.com> |
Actually, the first thing I should have asked is what version of snort are you using? Because this configuration is different for snort 2 and snort 3. Thanks, Vitalii! From: Winx Linx <[email protected]> Date: Monday, 28 August 2023, 20:11 To: Vitalii Serhiiovych Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]> Subject: Re: [Snort-users] how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]" thanks a lot vitalii but may i ask which file , that needs to be disabled On Mon, Aug 28, 2023 at 8:24 PM Vitalii Serhiiovych Horbatov -X (vhorbato - SOFTSERVE INC at Cisco) <[email protected]<mailto:[email protected]>> wrote: Hi winxlinx, in order to get rid of these alerts, you can use two ways: 1) if you think that this (lack of 3-way handshake) is normal for your traffic, you can use the stream_tcp.require_3whs parameter by setting it to -1. This will cause snort to process such sessions as a midstream, so doing full processing on them. 2) If you just don't want to see such alerts, you can use event filters or disable this rule using ips.states. Example: ips.states = [[ alert ( gid:129; sid:20; enable:no; ) ]] From my point of view, using stream_tcp.require_3whs here would be more correct. Thanks, Vitalii! From: Snort-users <[email protected]<mailto:[email protected]>> on behalf of Winx Linx via Snort-users <[email protected]<mailto:[email protected]>> Date: Monday, 28 August 2023, 16:35 To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: Re: [Snort-users] how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]" Hi Team, how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]" -- Regards winxlinx On Fri, Aug 25, 2023 at 11:40 PM Winx Linx <[email protected]<mailto:[email protected]>> wrote: Hi Team, how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]" -- Regards winxlinx On Fri, Aug 25, 2023 at 11:34 PM Winx Linx <[email protected]<mailto:[email protected]>> wrote: Hi Team, how do i disable the specific snort rule called "TCP session without 3-way handshake [**] [Classification: Potentially Bad Traffic]" -- Regards winxlinx -- Regards winxlinx -- Regards winxlinx -- Regards winxlinx _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette