Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » HTTP_INSPECT and ssl

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

HTTP_INSPECT and ssl


Posted by greymore57 on August 18, 2005 05:50:51

Hi People, although I don't consider myself an expert so I hope you don't mind me posting here :) I have a problem with http_inspect generating alerts, complaining of NON-RFC http delimiter, I think this is being triggered by a workstation using an ssl connection through a proxy server, the payload is of course encrypted, but is going to port 8080 on our proxy server. Is there any way to filter this or to prevent http_inspect seeing this as an issue.


Thanks in Advance

Graham

Posted by roesch on August 18, 2005 20:10:58

Use the suppress operator as a config option. Check out the README.thresholding file.