Snort mailing list archives

portscan problem


From: spy guy <spyguy703 () earthlink net>
Date: 20 Nov 2002 13:06:26 -0800

Snort thinks my Windows 2000 Active Directory server is scanning my MS
Exchange 2000 server.

TCP and UDP traffic

Some dest ports are random and high
Sometimes its 389/tcp (ldap)

Any ideas how to tweak portscan?
How do the thresholds work?
Anyone have a similar problem?

spp_portscan2





-------------------------------------------------------
This sf.net email is sponsored by: 
Battle your brains against the best in the Thawte Crypto 
Challenge. Be the first to crack the code - register now: 
http://www.gothawte.com/rd521.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: