|Main Archive Page > Month Archives > snort-users archives|
On Tue, 2009-11-24 at 11:13 -0500, Josh Smith wrote:
> I already did some testing with snort, and sent to cunningpike but
> didn't hit reply to all. Here it is so far:
> Snort was able to detect the "alternate" handshake if I took out
> http_method, and put in flow:established,from_server. This was odd,
> since it should alert on to_server being a GET request.
That should help the Snort crew to narrow things down... unless it's decided that it's not a problem. And I'm glad to hear that flow: works properly. Thanks for testing!