Snort mailing list archives

Snort_decoder question


From: "Hobgood, Frankie" <Frankie.Hobgood () DSM COM>
Date: Mon, 19 May 2003 13:21:59 -0500

I am seeing a large amount of alerts like the one below every day.  Both
addresses are internal address.  What line in the snort.conf file under the
snort decoder config do I need to uncomment to stop seeing these?

(snort_decoder): Short UDP packet, length field > payload length {UDP}
xxx.xxx.xxx.xxx:0 -> xxx.xxx.xxx.xxx:0

Thanks,
Frank Hobgood CCNA, NNCDS, SCP
Network Analyst II 
DSM Pharmaceuticals, Inc.
frankie.hobgood () dsm com


This e-mail is for the intended recipient only.
If you have received it by mistake please let us know by reply and then
delete it from your system; access, disclosure, copying, distribution or
reliance on any of it by anyone else is prohibited.
If you as intended recipient have received this e-mail incorrectly, please
notify the sender (via e-mail) immediately.


-------------------------------------------------------
This SF.net email is sponsored by: If flattening out C++ or Java
code to make your application fit in a relational database is painful, 
don't do it! Check out ObjectStore. Now part of Progress Software.
http://www.objectstore.net/sourceforge
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: