[Snort-devel] Snort 2.2.0 core

Andrew Rucker Jones arjones at ...2237...
Fri Nov 19 16:21:07 EST 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Not as such. We get warnings like that constantly (we've turned them off
in the meantime) because of faulty drivers for gigabit adapters, but we
have never had Snort dump core as a result. Sorry i can't be of more help.

		-&


Sudom, Don wrote:
| Hi,
|
| I had an incident whereby the snort process recorded the following
| Warning message and then core dumped.
|
| Nov  3 06:59:24 sprobe1 snort: [ID 702911 auth.alert] [116:46:1]
| (snort_decoder) WARNING: TCP Data Offset is less than 5! {TCP} a.b.c.d:0
| -> e.f.g.h:0
|
| Has anyone seen this issue?  I've searched the archives and have not
| found any hits.
|
| Regards,
| Don
|

- --
GPG key / Schlüssel -- http://simultan.dyndns.org/~arjones/gpgkey.txt
Encrypt everything. / Alles verschlüsseln.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFBnmKuoI7tqy5bNGMRAmPRAKDyE5U0OAurggvwrON0WgIlE196lACgnpRK
+PoTKXd9ByBmWuJn1jUPCnM=
=5qD+
-----END PGP SIGNATURE-----




More information about the Snort-devel mailing list