cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
343
Views
5
Helpful
1
Replies

ids sig 3201

stith
Level 1
Level 1

Alarm 3201 fired when user did a google search which included some words which are in the sig.

Alarm is a false postive. Should sig fire when only keywords appear? Attachment contains alarm contents.

1 Reply 1

mcerha
Level 3
Level 3

Agreed, the alarm is a false positive, but the signature did fire as it was designed to do. This signature is a catch-all for something that is usually suspicious to see in HTTP requests. Unfortunately, there isn't really anything we can do to prevent this type of problem without the use of filters or disabling the alarm. Perhaps it might make sense, to create filters for any UNIX web servers in your network. Or, just disable it outright.