Snort mailing list archives

Re: BAD-TRAFFIC loopback


From: Jeremy Hewlett <jh () sourcefire com>
Date: Tue, 6 Jan 2004 18:02:42 -0500

traffic Alert is NOW TFTPGET passwd
Reply-To: 
In-Reply-To: <200312231437.50172.matthew () rareearthstrategies com>
X-GPG-Fingerprint: 03C3 2E41 1D62 78F5 6F84  8B9B F182 4F90 9E45 EFA4
X-Quote: Ignotum per ignotius, obscurantum per obscurantius

On Tue, Dec 23, Matthew L. McCarty wrote:
I pretty much determined that they are due to the MS Blaster worm.  However 
these packets were setting off the BAD-TRAFFIC loopback 
traffic Alert as would make sense. But now all of the sudden they show up in 
the TFTPGET passwd alert instead.  

Could you check out the cvs HEAD branch (or snort-current from
http://www.snort.org/dl/snapshots/), and see if that fixes this
problem? 


-------------------------------------------------------
This SF.net email is sponsored by: IBM Linux Tutorials.
Become an expert in LINUX or just sharpen your skills.  Sign up for IBM's
Free Linux Tutorials.  Learn everything from the bash shell to sys admin.
Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: