Snort mailing list archives
Snort_decoder question
From: "Hobgood, Frankie" <Frankie.Hobgood () DSM COM>
Date: Mon, 19 May 2003 13:21:59 -0500
I am seeing a large amount of alerts like the one below every day. Both addresses are internal address. What line in the snort.conf file under the snort decoder config do I need to uncomment to stop seeing these? (snort_decoder): Short UDP packet, length field > payload length {UDP} xxx.xxx.xxx.xxx:0 -> xxx.xxx.xxx.xxx:0 Thanks, Frank Hobgood CCNA, NNCDS, SCP Network Analyst II DSM Pharmaceuticals, Inc. frankie.hobgood () dsm com This e-mail is for the intended recipient only. If you have received it by mistake please let us know by reply and then delete it from your system; access, disclosure, copying, distribution or reliance on any of it by anyone else is prohibited. If you as intended recipient have received this e-mail incorrectly, please notify the sender (via e-mail) immediately. ------------------------------------------------------- This SF.net email is sponsored by: If flattening out C++ or Java code to make your application fit in a relational database is painful, don't do it! Check out ObjectStore. Now part of Progress Software. http://www.objectstore.net/sourceforge _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort_decoder question Hobgood, Frankie (May 19)