[Snort-users] Portscan False Positives From My IP Range

Tobias Rice rice at ...7669...
Mon Apr 7 14:43:03 EDT 2003


 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Try entering this before your portscan2 line (with your ip, not 111.222.333.444):

preprocessor portscan2-ignorehosts: 111.222.333.444/32

and restart snortd

Good luck
Tobias

- -----Original Message-----
From: snort-users-admin at lists.sourceforge.net [mailto:snort-users-admin at ...3204...ts.sourceforge.net] On Behalf Of Vintinner, M. Scott
Sent: Monday, April 07, 2003 1:28 PM
To: 'snort-users at lists.sourceforge.net'
Subject: [Snort-users] Portscan False Positives From My IP Range

I'm getting a lot of portscans in my alert file where the source is my
network.  In this example, it looks like a user behind my firewall is simply
accessing a website:

[**] [117:1:1] (spp_portscan2) Portscan detected from 64.132.107.3: 21
targets 21 ports in 6 seconds [**]
04/07-16:22:07.580527 0:A0:8E:E:43:48 -> 0:B0:64:54:8A:21 type:0x800
len:0x3C
64.132.107.3:25320 -> 207.171.182.23:80 TCP TTL:127 TOS:0x0 ID:45683
IpLen:20 DgmLen:44 DF
******S* Seq: 0x1AC9FB  Ack: 0x0  Win: 0x2000  TcpLen: 24
TCP Options (1) => MSS: 1460


In my snort.conf file, my networks are configured so I would think portscan2
would ignore the traffic since its source is in HOME_NET.

var HOME_NET 64.132.107.0/24
var EXTERNAL_NET !64.132.107.0/24

Any suggestions?

Will the #preprocessor portscan-ignorehosts: 0.0.0.0 line work for
portscan2?

M. Scott Vintinner
Senior Systems Engineer
Robinson Bradshaw & Hinson, P.A.
101 N. Tryon St., Suite 1900
Charlotte, NC 28246
(704) 377-8189
mailto:scottv at ...8558...


- -------------------------------------------------------
This SF.net email is sponsored by: ValueWeb: 
Dedicated Hosting for just $79/mo with 500 GB of bandwidth! 
No other company gives more support or power for your dedicated server
http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPpHwncNinOuDXR1bEQL8jwCgtKiVXyhQt5Q6uE02zolnncZz2tgAn18m
7XEKKNSK/PDMaCDhgX3B9DRL
=rKMr
-----END PGP SIGNATURE-----





More information about the Snort-users mailing list