Snort mailing list archives

Re: STEALTH ACTIVITY (unknown) detection


From: cc <cc () belfordhk com>
Date: Wed, 30 Jul 2003 17:01:48 +0800

IntegPatchMgr wrote:

Hi,

Can any one let me know what below alert means ??

EVENT # :     531     
EVENTLOG :    Application     
EVENT TYPE :  INFORMATION (4) 
SOURCE :      snort   
EVENT ID :    1       
TIME :        7/28/2003 3:06:08 PM    
MESSAGE :     [111:1:1] (spp_stream4) STEALTH ACTIVITY (unknown)
detection {TCP} 192.168.230.148:1570 -> 192.168.200.100:80    


I'd like to know myself.  I'm getting quite A LOT lately.




-- 
email: cc () belfordhk com  | "A man who knows not where he goes,
                         |  knows not when he arrives."
                         |                - Anon


** All information contained in this email is strictly     **
** confidential and may be used by the intended receipient **
** only.                                                   **


Current thread: