Gregory D Hough
mr6re9 at ...6025...
Thu Jun 20 05:10:03 EDT 2002
I have snort listening on my gateway nic and was curious about all the
spp_portscan alerts logged from a win box inside the network. Mulling over
the faq's I see how to ignore this host, but would like to know WHY first.
Can anyone offer a simple explanation as to WHY there are so many portscan
alerts from this win box?
More information about the Snort-users