Snort mailing list archives

Re: How to disable the alert for "spp_portscan2"


From: Jochen Erwied <mack+snort-users () joker gnuu de>
Date: Wed, 13 Nov 2002 07:25:43 +0100

on Wednesday, November 13, 2002 06:07 you wrote:

(spp_portscan2) Portscan detected from xxx.xxx.xxx.xxx: 4 targets 21 ports
in 13 seconds

This is a false positive, and i wanted to disable this signature, however i
can't find this alert in any of the rules files,

It's inside snort.conf, so disable or configure it there (preprocessor
portscan2)

-- 
Jochen Erwied     | home: jochen () erwied de     +49-208-38800-18, FAX: -19
Sauerbruchstr. 17 | work: joe () mbs-software de  +49-2151-7294-24, FAX: -50
D-45470 Muelheim  | First sightings... <1672 () laura UUCP> 1989/10/11 18:06



-------------------------------------------------------
This sf.net email is sponsored by: Are you worried about 
your web server security? Click here for a FREE Thawte 
Apache SSL Guide and answer your Apache SSL security 
needs: http://www.gothawte.com/rd523.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: