[Snort-users] is there anyway of stoping this?

Ben Johansen benj at ...2026...
Thu May 31 12:14:52 EDT 2001

Hi All.

I have looked at whitehats.com and found not direct reference to this

--start log view---
05/31-01:53:39.840000  [**] spp_portscan: PORTSCAN DETECTED from (STEALTH) [**]
05/31-01:54:32.255000  [**] spp_portscan: portscan status from 1 connections across 1 hosts: TCP(1), UDP(0) STEALTH [**]
05/31-01:55:35.155000  [**] spp_portscan: End of portscan from TOTAL time(0s) hosts(1) TCP(1) UDP(0) STEALTH [**]
--end log view---

Can it be stopped?
Is there a hole I have missed?

Ben Johansen
Newbie 3rd class

More information about the Snort-users mailing list