[Snort-users] [Q] Socks server - NEWBIE!!!

mitiste at ...1065... mitiste at ...1065...
Wed Jan 3 18:13:24 EST 2001


	I have a question for the gurus: is there any way I could 
possibly reduce/filter the "noise" coming from monitoring a proxy 
server with socks services enabled (as those services could be 
picking up any port), by - perhaps - running in parallel a "netstat-
sort-of" command, and comparing real socks connections with 
possible exploit attempts?

TIA,
Stef	





More information about the Snort-users mailing list