[Snort-users] spp_portscan to port 80
daveyn2002 at ...3162...
Thu Feb 21 10:18:04 EST 2002
Thanks, i did have my home net set to any.
So why would it think port 80 traffic is a port scan?
--- Paul Keser <pkeser at ...4934...> wrote: >
-----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> I saw a lot of these types of alerts until I defined
> my HOME_NET variable.
> - -PaulK
> On Thursday 21 February 2002 08:48, you wrote:
> > Hi,
> > I have set up snort and my portscan.log file is
> > of spp_portscans from my internal addresses to
> > addresses on port 80. I put this down to normal
> > traffic, is it normal and why does it happen?
> > Thank you.
> > http://movies.yahoo.com.au - Yahoo! Movies
> > - Vote for your nominees in our online Oscars
> > _______________________________________________
> > Snort-users mailing list
> > Snort-users at lists.sourceforge.net
> > Go to this URL to change user options or
> > Snort-users list archive:
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.0.6 (GNU/Linux)
> Comment: For info see http://www.gnupg.org
> -----END PGP SIGNATURE-----
http://movies.yahoo.com.au - Yahoo! Movies
- Vote for your nominees in our online Oscars pool.
More information about the Snort-users