[Snort-users] wingate 8080 attempt?

Mike McNally mmcnally3 at ...544...
Sun Oct 1 21:33:37 EDT 2000


grep 8080 /etc/snort
  scan-lib:alert tcp any any -> $HOME_NET 8080 (msg:"WinGate 8080 Attempt"; flags: S;)
  snort-lib:preprocessor http_decode: 80 443 8080

I am getting a log everytime my other pc (win98 eth0 connected 
to samba/firewall/linuxbox) accesses the 8080 port to utilize
wwwoffle proxy service.  Should I just comment out the line 
from the scan-lib file?
-- 

Mike McNally		mmcnally3 at ...544...



More information about the Snort-users mailing list