Open GoogleCodeExporter opened 9 years ago
@andres
Scalp! alerts are based on PHPIDS. If you find false positives please let them
know
by posting this information to the PHPIDS filters forum:
http://forum.php-ids.org/?CategoryID=8
Thank you,
Don C. Weber
Original comment by cutaways...@gmail.com
on 29 Dec 2008 at 8:52
Ok, but in the PHP-IDS they'll tell me that it's a scalp problem :(
Original comment by andres.riancho@gmail.com
on 29 Dec 2008 at 8:55
@cutawaysecurity:
It is absolutely possible that the problem is due to scalp. Even if the regexp
are coming from the
PHP-IDS project, there are some manipulation to do on the log lines in order to
decrease the
false-negative/positive.
Especially this part:
http://code.google.com/p/apache-scalp/source/browse/branches/scalp-0.4.py#226
@andres:
Thanks for the report, I will look at this when I have a bit more time. It
looks like these are
bad false-positive, these are simple GET content
Original comment by romain.g...@gmail.com
on 29 Dec 2008 at 9:04
@andres
Sorry about the confusion.
@romain
I apologize, I thought this was a no brainer.
Original comment by cutaways...@gmail.com
on 29 Dec 2008 at 10:25
Changed ownership
Original comment by cutaways...@gmail.com
on 29 Dec 2008 at 11:00
Original comment by romain.g...@gmail.com
on 9 Jan 2009 at 12:23
I use
----
./scalp-0.4.py -l ./logs/access_log.90.gz -f ./default_filter.xml -o
./scalp-output
--html
------
Original comment by kendall....@gmail.com
on 12 May 2009 at 2:10
Original issue reported on code.google.com by
andres.riancho@gmail.com
on 29 Dec 2008 at 2:01