Snort mailing list archives

Re: lots of ttl evasion attempt alerts snort 1.8.7


From: "David E. Gianndrea" <daveg () comsquared com>
Date: Fri, 12 Jul 2002 14:16:34 -0400



Chris Green wrote:

Michael Scheidell <scheidell () secnap net> writes:

I won't say BILLIONS, but 200 more of these in 21 hours of running snort
1.8.7 vs 1.8.6beta6.

starting snort thus:
/usr/local/bin/snort -doDI -m 022 -z \
-c /usr/local/etc/snort.conf -i rl0 -l /var/log/snort

system is FBSD 4.5.

I did not change my snort.conf:
preprocessor frag2
preprocessor stream4: noinspect, disable_evasion_alerts

Add ttl_limit 0


Would somebody please explain this change. I too have been seeing
these alerts, but im not quite sure I understand what they are, and
what the effect of this change are.


-- 
David Gianndrea
Senior Network Engineer
Comsquared Systems, Inc.


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Gadgets, caffeine, t-shirts, fun stuff.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: