[Snort-sigs] spp_stream4 Steath activity

John Hally JHally at ...1106...
Fri May 30 11:34:08 EDT 2003


Hello All,

I'm seeing a good amount of these alerts coming from the stream4
preprocessor.  For the most part the payload of the packets look normal, but
they all have ACK,PUSH,RST set.   Has anyone else seen this behavior?  The
traffic is originating from a proxy of some sort and destined for an
2000/IIS5 server, if that helps.

John H.




More information about the Snort-sigs mailing list