[Snort-sigs] What does this mean?

Dale L. Handy dhandy at ...1244...
Tue Jul 1 10:36:22 EDT 2003


I'll try (there are folks that can answer this better).

This is a message from the Stream-4 snort pre-processor -- there was 
some stealth activity detected in the stream from 142.167.32.146, port 
1701, directed at your web server, port 80.  You apparently configured 
Snort to use the Stream-4 preprocessor.  It didn't like something in the 
traffic stream, and generated an alert.

Michael Breton wrote:

>I have been receiving he following info in my log regularly.  What does it
>mean?
>
>Jun 29 14:50:50 special snort: [ID 702911 auth.alert] [111:1:1]
>(spp_stream4) STEALTH ACTIVITY (unknown) detection {TCP} 142.167.32.146:1701
>-> my.web.server.address:80
>
>Should I be concerned?
>
>Thanks,
>
>______________________________
>Michael Breton
>Network Engineer | Commtel
>117 Main Street | Winthrop | Maine | 04364
>Voice 207.377.9814 | Fax 207.377.3911
>mbreton at ...1645...
>
>
>-------------------------------------------------------
>This SF.Net email sponsored by: Free pre-built ASP.NET sites including
>Data Reports, E-commerce, Portals, and Forums are available now.
>Download today and enter to win an XBOX or Visual Studio .NET.
>http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
>_______________________________________________
>Snort-sigs mailing list
>Snort-sigs at lists.sourceforge.net
>https://lists.sourceforge.net/lists/listinfo/snort-sigs
>
>
>  
>

-- 
"The trouble with doing something right the first time 
 is that nobody appreciates how difficult it was."

-- Dale L. Handy, P.E.
   dhandy at ...1244...
   http://www.nitrodata.com






More information about the Snort-sigs mailing list