[Snort-sigs] syn/fin scans from stream4
Brian.Perry at ...1819...
Thu Aug 28 11:50:01 EDT 2003
Yeah, no doubt, I'd like to pass that traffic too, even better would be
a $VULN_SCANNER variable for conf file to dump IPs in.
From: Vincent Vono [mailto:vincent.vono at ...1538...]
Sent: Thursday, August 28, 2003 1:06 PM
To: snort-sigs at lists.sourceforge.net
Subject: [Snort-sigs] syn/fin scans from stream4
Anyone know how to pass syn/fin scans from a specific source address?
events are being triggered by the preprocessor stream4. I have a
scanner, when scanning, this event is triggered. Want to stop this from
triggering from this specific source address.
I've searched thru the docs but find nothing.
******************* PLEASE NOTE *******************
This E-Mail/telefax message and any documents accompanying this
transmission may contain privileged and/or confidential information and
intended solely for the addressee(s) named above. If you are not the
intended addressee/recipient, you are hereby notified that any use of,
disclosure, copying, distribution, or reliance on the contents of this
E-Mail/telefax information is strictly prohibited and may result in
action against you. Please reply to the sender advising of the error in
transmission and immediately delete/destroy the message and any
accompanying documents. Thank you.
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
Snort-sigs mailing list
Snort-sigs at lists.sourceforge.net
This electronic message, including any attachments, is confidential and intended solely for use of the intended recipient(s). This message may contain information that is privileged or otherwise protected from disclosure by applicable law. Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. If you have received this message in error, please delete it and notify the sender immediately.
More information about the Snort-sigs