Snort mailing list archives

Taking action on exploit attempts


From: Pratik Narang <pratik.cse.bits () gmail com>
Date: Sat, 22 Sep 2012 16:02:24 +0530

Asking this as a general opinion of experienced users...

Just now I see I have had about 40 hits in one second for the rule 1:16008,
which corresponds to CVE-2007-6239:WEB-MISC Multiple Products excessive
HTTP 304 Not Modified responses exploit
attempt<http://www.snort.org/search/sid/16008>
    In this particular case, do I need to do anything?

    What does general wisdom say in this regard? - should such one-off hits
be taken seriously and some action be taken, like blocking the source IP?
(well I just run Snort in IDS mode, so I cant actually take any action, but
wanted to know this to have more understanding of this) Or should admins
usually wait to see repeated hits before deciding that this is not some
false trigger but an actual alert?

Thanks
------------------------------------------------------------------------------
How fast is your code?
3 out of 4 devs don\\\'t know how their code performs in production.
Find out how slow your code is with AppDynamics Lite.
http://ad.doubleclick.net/clk;262219672;13503038;z?
http://info.appdynamics.com/FreeJavaPerformanceDownload.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: