[Snort-devel] RFE: ignore_ports option for sfportscan preprocessor

Alex Butcher, ISC/ISYS Alex.Butcher at ...2437...
Fri Feb 11 02:47:32 EST 2005


Hi -

As P2P traffic looks a lot like portscanning, it'd be nice to be able to 
tell sfportscan to ignore the common P2P ports. Sadly, I suspect this would 
be quite difficult to add with Snort <= 2.3.0.

Any comments?

Best Regards,
Alex.
-- 
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9






More information about the Snort-devel mailing list