Snort mailing list archives
HOW TO DECODE SNORT MESSAGES
From: "suresh" <bsuresh1976 () hotmail com>
Date: Wed, 29 Nov 2006 14:29:48 +0530
Hi, Is there any way on the internet to decode the below messages? v 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1878 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 last message repeated 3 times Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [122:19:0] (portscan) UDP Portsweep {PROTO255} 66.114.175.16 -> 192.168.252.129 Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1949 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1949 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1878 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1878 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1949 -> 219.139.108.138:80 Nov 29 08:55:58 HOME-sj-ids-int01 last message repeated 3 times Nov 29 08:55:59 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1878 -> 219.139.108.138:80 Nov 29 08:55:59 HOME-sj-ids-int01 snort[6321]: [1:0:1] outbound port 80 investigation - Added by AS {TCP} 192.168.203.131:1878 -> 219.139.108.138:80 Nov 29 08:55:59 HOME-sj- Suresh
------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Ron Jenkins (Nov 28)
- Re: Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Joel Esler (Nov 28)
- HOW TO DECODE SNORT MESSAGES suresh (Nov 29)
- Re: HOW TO DECODE SNORT MESSAGES Eric Hines (Nov 29)