[Snort-users] SHELLCODE x86 NOOP

Basil Saragoza snortlst at ...125...
Thu Mar 7 10:53:31 EST 2002


I have quite a lot of them on my internal sensor, all coming from port 80, I
took a look at the payload and it doesn't explain much to me.....
Would it be O.K to say that those are false alarms generated from nrmal http
traffic?




More information about the Snort-users mailing list