If you can't upgrade immediately, you should disable the RPC preprocessor:
If you are in an environment that can not upgrade snort immediately, comment out the line in your snort.conf that begins:
preprocessor rpc_decode
and replace it with:
# preprocessor rpc_decode




Reply With Quote