@simby:
Bill can you please share your list or. PM? Please,..
Here is what I have on my home firewall. I have not added or removed entries in quite some time…
#"(http_inspect) JAVASCRIPT WHITESPACES EXCEEDS MAX ALLOWED"
suppress gen_id 120, sig_id 10
#"(http_inspect) HTTP RESPONSE HAS UTF CHARSET WHICH FAILED TO NORMALIZE"
suppress gen_id 120, sig_id 4
#"(http_inspect) NON-RFC DEFINED CHAR"
suppress gen_id 119, sig_id 14
#(http_inspect) IIS UNICODE CODEPOINT ENCODING
suppress gen_id 119, sig_id 7
#"BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt"
suppress gen_id 1, sig_id 16482
#"ET TROJAN Suspicious Malformed Double Accept Header"
suppress gen_id 1, sig_id 2008975
#"GPL WEB_CLIENT PNG large colour depth download attempt"
suppress gen_id 1, sig_id 2103134
#"FILE-IDENTIFY download of executable content"
suppress gen_id 1, sig_id 11192
#"FILE-IDENTIFY Portable Executable binary file magic detected"
suppress gen_id 1, sig_id 15306
#ET SCAN Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection
suppress gen_id 1, sig_id 2013479
#ET SCAN Behavioral Unusually fast Terminal Server Traffic, Potential Scan or Infection
suppress gen_id 1, sig_id 2013479
#ET INFO Packed Executable Download
suppress gen_id 1, sig_id 2014819
#(smtp) Attempted response buffer overflow: 1448 chars
suppress gen_id 124, sig_id 3
#(http_inspect) UNESCAPED SPACE IN HTTP URI
suppress gen_id 119, sig_id 33
#(http_inspect) TOO MANY PIPELINED REQUESTS
suppress gen_id 119, sig_id 34