Snort mailing list archives
Re: BAD-TRAFFIC loopback
From: Jeremy Hewlett <jh () sourcefire com>
Date: Tue, 6 Jan 2004 18:02:42 -0500
traffic Alert is NOW TFTPGET passwd Reply-To: In-Reply-To: <200312231437.50172.matthew () rareearthstrategies com> X-GPG-Fingerprint: 03C3 2E41 1D62 78F5 6F84 8B9B F182 4F90 9E45 EFA4 X-Quote: Ignotum per ignotius, obscurantum per obscurantius On Tue, Dec 23, Matthew L. McCarty wrote:
I pretty much determined that they are due to the MS Blaster worm. However these packets were setting off the BAD-TRAFFIC loopback traffic Alert as would make sense. But now all of the sudden they show up in the TFTPGET passwd alert instead.
Could you check out the cvs HEAD branch (or snort-current from http://www.snort.org/dl/snapshots/), and see if that fixes this problem? ------------------------------------------------------- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell to sys admin. Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: BAD-TRAFFIC loopback Jeremy Hewlett (Jan 06)