Snort mailing list archives

help with entries in alert file - RPC portmap request and ICMP superecho scan


From: Paul Millar <dazzlepm () lineone net>
Date: Wed, 10 Oct 2001 22:55:03 +0100

As a new user of snort I have recieved a couple of entries in my snort alert file which I need more information on and wether they are anything to be worried about.

I've had two 'RPC portmap request rstad' and one 'ICMP superecho scan' and two of the IP addresses where they have come from do not resolv to anything meaningful and they are all Classified as 'Attempted Information Leak'.

I am running a RedHat 6.2 server to act as a modem sharing server for a small home network.

All help appreciated,

Paul


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: