snort blocks request problems
"chuyu.ouyang--- via Snort-users" <[email protected]> Mon, 8 Jul 2024 14:20:56 +0800
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hello, I installed snort on my pfsense firewall.My firewall wan port address is :49.235.183.227 I made a dnat with port 49493 pointing to a machine on the same subnet as the firewall lan port. I am now submitting a request by using curl to attach some data to an http request with a string of keys attached.My firewall wan port address is :49.235.183.227 I made a dnat with port 49493 pointing to a machine on the same subnet as the firewall lan port. I am now submitting a request by using curl to attach some data to an http request with a string of keys attached.This url request looks something like http://49.235 183.227:49439 / pair? uniqueid=0123456789ABCDEF&uuid=58e6256db1c24a6b97022f97f0ba1e1c&devicename=roth&updateState=1&phrase=getservercert&salt= bc46989a6a48cad0ec9f5ab696dac8d1&clientcert=2d2d2d2d2d424547494e2043455254494649434154452d2d2d2d2d0456752.When I don't have snort installed, my requests are sent successfully, but when I have snort installed, with the snort interface enabled, blocking mode and ips policy enabled, my requests fail to be submitted. Specifically, the last field in the request is clientcert. When I don't write it, the request will be submitted successfully, but if I write it, it will fail. I'm wondering if snort blocks certain request fields.Thank you! [email protected] _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette