Snort mailing list archives

Re: Source 0.0.0.0 Destination 0.0.0.0


From: twig les <twigles () yahoo com>
Date: Sat, 29 Mar 2003 14:16:57 -0800 (PST)

I get those all the time because our proprietardy firewall
mangles packets and no one knows why.  Throw TCPdump on the wire
and sniff for those src/dst and get the full packet.  When I did
that I found the culprit via MAC address and saw that the
checksum was invalid.

--- Nels <nelsbels () amerion com> wrote:
Ladies and Gentlemen,

            I'm trying to figure out my alerts.   I have been
getting ICMP
and a few PORN rule alerts that come from source address
0.0.0.0 and
destination address 0.0.0.0.  How do I resolve this?  Also, I
would like to
specify my smtp servers in the config, how do I enter multiple
smtp servers:
xxx.xxx.xxx.xxx/32,xxx.xxx.xxx.xxx/32?  Any spaces?  Thanks in
advance.  


ATTACHMENT part 2 application/ms-tnef name=winmail.dat



=====
-----------------------------------------------------------
Know yourself and know your enemy and you will never fear defeat.         
-----------------------------------------------------------

__________________________________________________
Do you Yahoo!?
Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!
http://platinum.yahoo.com


-------------------------------------------------------
This SF.net email is sponsored by:
The Definitive IT and Networking Event. Be There!
NetWorld+Interop Las Vegas 2003 -- Register today!
http://ads.sourceforge.net/cgi-bin/redirect.pl?keyn0001en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: