From: Will M. <wil...@gm...> - 2008-07-30 16:16:13
|
so your telling me that you are getting alerts but not drops for web rules? Regards, Will On 30 Jul 2008 15:14:49 -0000, vishal_nitr <vis...@re...> wrote: > Hi All, > I am using Snort_inline-2.6.1.5 and ftester1.0 to test snort IPS. > Snort is not able block only web related packets. > Actually ftester will use snort rule files to generate packets means it > generates packets according to the rules mentioned in rule files. > When I use any other rule files like bad-traffic.rules or misc.rules > or exploit.rules to generate packets Snort is detecting and dropping them > but when I am using web-iis.rules or bleeding-web.rules it is checking those > packets but not dropping it. > > TIA. > > > > Thanks and Regards, > Vishal Kotalwar, > Software Engineer, > Aricent, > Chennai-35. > 09884074047. > > ------------------------------------------------------------------------- > This SF.Net email is sponsored by the Moblin Your Move Developer's challenge > Build the coolest Linux based applications with Moblin SDK & win great > prizes > Grand prize is a trip for two to an Open Source event anywhere in the world > http://moblin-contest.org/redirect.php?banner_id=100&url=/ > _______________________________________________ > Snort-inline-users mailing list > Sno...@li... > https://lists.sourceforge.net/lists/listinfo/snort-inline-users > > |