Hi,
I got a number of attacks like:
WEB-PHP PayPal Storefront arbitrary command execution attempt
So I wanted to drop the connection when snort detects this alert. I modified the IPS rulebase to drop the connection when an alert comes through.
But nothing happens. I can visit the website normaly and I still get the alert massage from snort.
What did I wrong?
Why the connection deosn´t drop??
Thanks for responses!
This thread was automatically locked due to age.