Snort mailing list archives
Re: How to disable the alert for "spp_portscan2"
From: Jochen Erwied <mack+snort-users () joker gnuu de>
Date: Wed, 13 Nov 2002 07:25:43 +0100
on Wednesday, November 13, 2002 06:07 you wrote:
(spp_portscan2) Portscan detected from xxx.xxx.xxx.xxx: 4 targets 21 ports in 13 seconds
This is a false positive, and i wanted to disable this signature, however i can't find this alert in any of the rules files,
It's inside snort.conf, so disable or configure it there (preprocessor portscan2) -- Jochen Erwied | home: jochen () erwied de +49-208-38800-18, FAX: -19 Sauerbruchstr. 17 | work: joe () mbs-software de +49-2151-7294-24, FAX: -50 D-45470 Muelheim | First sightings... <1672 () laura UUCP> 1989/10/11 18:06 ------------------------------------------------------- This sf.net email is sponsored by: Are you worried about your web server security? Click here for a FREE Thawte Apache SSL Guide and answer your Apache SSL security needs: http://www.gothawte.com/rd523.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How to disable the alert for "spp_portscan2" MOHESOWA BYAS (Nov 12)
- Re: How to disable the alert for "spp_portscan2" Jochen Erwied (Nov 12)