Snort mailing list archives

SCAN Proxy (8080) attempt


From: Marcel <error79 () gmx de>
Date: 06 Jul 2003 19:09:56 +0200

Hallo

I am having following problem.
Snort is running on the externel interface and there is also running a
Squid Daemon on the internal interface listening on port 8080.
The Internal Network is beeing set up as "homenetwork".
Now everytime one of the internal Clients is surfing the net, snort
gives me following "Scan Proxy attempt" message.

Jun 16 10:49:47 *** snort: [1:620:2] SCAN Proxy (8080) attempt
[Classification: Attempted Information Leak] [Priority: 2]: {TCP}
192.168.181.86:50358 -> 192.168.181.222:8080

Can someone tell me how to get rid of these annoying messages?

Thanks in advance

Marcel



-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: