Snort mailing list archives
Re: Would you suspect?
From: Chris Green <cmg () sourcefire com>
Date: Thu, 11 Apr 2002 09:21:00 -0400
"Ronneil Camara" <ronneilc () remingtonltd com> writes:
Hi guys, I am receiving a lot of alerts from my snort, WEB-MISC 403 Forbidden. The source is actually our web server going to a public ip address. Would you suspect that the destination ip is trying to hopefully, make a dir listing of our virtual directory? What's your analysis?
yup typically. Are there any other alerts related to the public ip? -- Chris Green <cmg () sourcefire com> "Yeah, but you're taking the universe out of context." _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Would you suspect? Ronneil Camara (Apr 11)
- Re: Would you suspect? Chris Green (Apr 11)
- <Possible follow-ups>
- RE: Would you suspect? Ronneil Camara (Apr 11)
- RE: Would you suspect? Sheahan, Paul (PCLN-NW) (Apr 11)
- RE: Would you suspect? Ronneil Camara (Apr 11)