Snort mailing list archives
How to disable the alert for "spp_portscan2"
From: MOHESOWA BYAS <byasmohesowa () sbm intnet mu>
Date: Wed, 13 Nov 2002 09:07:37 +0400
Hi, I'm getting lots of the following event: (spp_portscan2) Portscan detected from xxx.xxx.xxx.xxx: 4 targets 21 ports in 13 seconds This is a false positive, and i wanted to disable this signature, however i can't find this alert in any of the rules files, Can anyone please help, I just want to know the rules file in which this signature is located, and the actual rule if possible My database is getting to much of these false positives in the order or 100,000!! Thanks & Regards ########################################### This message has been scanned by F-Secure Anti-Virus for Microsoft Exchange. For more information, connect to http://www.F-Secure.com/ ------------------------------------------------------- This sf.net email is sponsored by: To learn the basics of securing your web site with SSL, click here to get a FREE TRIAL of a Thawte Server Certificate: http://www.gothawte.com/rd522.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- How to disable the alert for "spp_portscan2" MOHESOWA BYAS (Nov 12)
- Re: How to disable the alert for "spp_portscan2" Jochen Erwied (Nov 12)