Snort mailing list archives

How to disable the alert for "spp_portscan2"


From: MOHESOWA BYAS <byasmohesowa () sbm intnet mu>
Date: Wed, 13 Nov 2002 09:07:37 +0400

Hi, I'm getting lots of the following event:

(spp_portscan2) Portscan detected from xxx.xxx.xxx.xxx: 4 targets 21 ports
in 13 seconds

This is a false positive, and i wanted to disable this signature, however i
can't find this alert in any of the rules files,


Can anyone please help, I just want to know the rules file in which this
signature is located, and the actual rule if possible

My database is getting to much of these false positives in the order or
100,000!!

Thanks & Regards
###########################################

This message has been scanned by F-Secure Anti-Virus for Microsoft Exchange.
For more information, connect to http://www.F-Secure.com/


-------------------------------------------------------
This sf.net email is sponsored by: 
To learn the basics of securing your web site with SSL, 
click here to get a FREE TRIAL of a Thawte Server Certificate: 
http://www.gothawte.com/rd522.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: