[Snort-users] Bare byte alerts but no non-ASCII characters!

This is a discussion on [Snort-users] Bare byte alerts but no non-ASCII characters! within the Snort forums, part of the System Security and Security Related category; I'm looking at several "BARE BYTE UNICODE ENCODING" alerts, and wondering w= hy = are triggered, because as ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-21-2008
Julio Cesar Gazquez
 
Posts: n/a
Default [Snort-users] Bare byte alerts but no non-ASCII characters!

I'm looking at several "BARE BYTE UNICODE ENCODING" alerts, and wondering w=
hy =

are triggered, because as far as I understand it, it means there are =

non-ASCII, non percent encoded characters in the request.

However, all the bytes in the payload (at least as shown in BASE, and I don=
't =

have favorite suspects), are in the sub 0x80 range.

Any ideas about why this is happening? They aren't the only weird alerts I'=
ve =

got, but one of the most prevalent.

-- =

Julio C=E9sar G=E1zquez
Seguridad Inform=E1tica -- Int. 736
Municipalidad de Rosario

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...=3Dsnort-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:02 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0