[Snort-users] spp_stream4 possible EVASIVE RST

KD Rajkumar koderma at ...125...
Tue Apr 15 06:50:26 EDT 2003


What would cause Snort to generate the following message:

Apr 14 15:58:31 testbox.test.com snort: [111:2:1] (spp_stream4) possible 
EVASIVE RST detection {TCP} 192.168.128.200:35800 -> 192.168.64.115:4031

It's happened a few times today. The testbox in question has recently been 
re-IPed.

I am running Snort 1.9 on RHL 7.3. Also, where should I look to see what is 
causing the pre-processor to alert on this packet ?

Thanks.

_________________________________________________________________
The new MSN 8: smart spam protection and 2 months FREE*  
http://join.msn.com/?page=features/junkmail





More information about the Snort-users mailing list