In article <3e5628fc$1@news.povray.org> , "Rick [Kitty5]" <ric### [at] kitty5com>
wrote:
> Why is the povray.org news server filling my snort logs with
Because your intrusion detection system is defective and reporting nonsense?
Thorsten
____________________________________________________
Thorsten Froehlich, Duisburg, Germany
e-mail: tho### [at] trfde
Visit POV-Ray on the web: http://mac.povray.org
On Fri, 21 Feb 2003 13:21:26 -0000
"Rick [Kitty5]" <ric### [at] kitty5com> wrote:
> Why is the povray.org news server filling my snort logs with
A look at the snort rule quickly reveals that anything containing
"200 " and with a size >100, will be logged. An IDS is not an AI system,
it depends on the mantainer to investigate and remove false positives.
It's a hard work, but at some point you will have it nicely configured
to no report too many false positives.
--
Jaime Vives Piqueres
La Persistencia de la Ignorancia
http://www.ignorancia.org