Re: established connection and ids signatures

Josh Berry <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
I believe that the -z option is deprecated and not needed anymore with
the improvements in stream4.  Marty posted to this list a couple of
weeks ago saying that the option would probably not even be available in
upcoming releases.

On Mon, 2004-08-30 at 07:10, lola marais wrote:
> >This used to be accomplished with the -z switch. You might want to take
> >a look at deactivating the stream4 preprocessor in snort.conf, too.
> 
> thanks andrew,
> 
> i disabled the following parameters and it worked. the snort process no 
> longer looks at the state of the session when the binary files are 
> re-passed.
> 
> # preprocessor stream4: disable_evasion_alerts
> # preprocessor stream4_reassemble
> 
> _________________________________________________________________
> Access your MSN favourites from anywhere - download MSN Toolbar today! 
> http://toolbar.msn.co.za?DI=1054&XAPID=2083
> 
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
-- 


Josh Berry | CISSP GCIA
Network Security Engineer
214-765-1296

--------------------------------------------------------------------
If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
	-- (Former) White House Cybersecurity adviser Richard Clarke
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.