[Snort-users] wingate 8080 attempt?

Mike McNally mmcnally3 at ...544...
Sun Oct 1 21:33:37 EDT 2000

grep 8080 /etc/snort
  scan-lib:alert tcp any any -> $HOME_NET 8080 (msg:"WinGate 8080 Attempt"; flags: S;)
  snort-lib:preprocessor http_decode: 80 443 8080

I am getting a log everytime my other pc (win98 eth0 connected 
to samba/firewall/linuxbox) accesses the 8080 port to utilize
wwwoffle proxy service.  Should I just comment out the line 
from the scan-lib file?

Mike McNally		mmcnally3 at ...544...

More information about the Snort-users mailing list