[Snort-users] Portscan 2 question

Soren Macbeth smacbeth at ...7281...
Thu Oct 24 11:04:04 EDT 2002


Looks at the ports that portscan2 reported. Sometime clients browsing
websites cause portscan2 to trigger based on the fact that some browsers
initiate a new connection (and thus, new port) for each image. If you
haven't change the config, there should be a scan.log file in your snort log
directory which will have more info.

//soren 

-----Original Message-----
From: Joe Giles [mailto:jgiles at ...6534...] 
Sent: Thursday, October 24, 2002 1:23 PM
To: Snort-List
Subject: [Snort-users] Portscan 2 question

I have a weird problem with 2 entries in my ACID database. Apparently,
my server did a port scan on a remote machine. The problem is that no
one here initiated a port scan. The database lists my server IP as the
source and lists a dest IP. This is listed as a spp_portscan2. Does the
new snort scan other machines on the Internet? I don't want any issues
with other services because they think I'm port scanning their network.

Thanks

Joe





-------------------------------------------------------
This sf.net email is sponsored by: Influence the future 
of Java(TM) technology. Join the Java Community 
Process(SM) (JCP(SM)) program now. 
http://ads.sourceforge.net/cgi-bin/redirect.pl?sunm0003en
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list