Snort mailing list archives
SCAN UPnP service discover attempt
From: "Martin Jr., D. Michael" <martinm () montevallo edu>
Date: Wed, 15 Oct 2003 15:37:28 -0500
Well I finally think I have my log file delimma solved (Thank you SwordSoft and VIA) but no comes the big job, sorting out all this information. One big thing is the large number of host that apparently are coming-up as "SCAN UPnP service discover attempt". My research on this has been a mixed back. Some say this can be serious and others say it is a side effect of XP machines. Keeping in mind that I am seeing this in a University environment with residence hall student network traffic... Is the "SCAN UPnP service discover attempt" something I should worry about? If so, how so? If not, why not and how can I remove it from my log alerts (I can't find what rule in Snort may be creating this alert). Any help would be appreciated. Thanks, Michael ------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US provide better services: Click here: http://sourceforge.net/supporters.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- RE: SCAN UPnP service discover attempt Schmehl, Paul L (Oct 15)
- <Possible follow-ups>
- SCAN UPnP service discover attempt Martin Jr., D. Michael (Oct 15)
- RE: SCAN UPnP service discover attempt Philip Davidson (Oct 16)
- Re: SCAN UPnP service discover attempt Michael . Mulholland (Dec 30)
- RE: Re: SCAN UPnP service discover attempt Brian F. Vaughan (Dec 30)
- Re: SCAN UPnP service discover attempt Michael . Mulholland (Dec 30)