Actions
Bug #159
closedFP on suricata v0.9.0 and today git with icmp not size zero
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hi,
First, thx you all for your good work!
I have a FP with joigned pcap:
09/03/08-08:15:15.425081 [**] [1:469:3] ICMP PING NMAP [**] [Classification: Attempted Information Leak] [Priority: 3] {1} 172.26.16.45:8 -> 172.26.9.163:0
I resend old signature id 469:
alert icmp any any -> any any (msg:"ICMP PING NMAP"; dsize:0; itype:8; classtype:attempted-recon; sid:469; rev:3;)
Anyone confirm this FP please? (alert with suricata v0.9.0 and suricata git today)
Regards
Rmkml
Files
Actions