[Snort-users] SCAN Proxy (8080) attempt

Andre Cameron andrec at ...9609...
Sun Jul 6 11:09:07 EDT 2003


I use snort center and just added a pass rule.  You cen get the details 
from the Snort Enterprise Installation guide located here:
http://users.pandora.be/larc/documentation/

Its on page 25 I think.

aNc


Marcel wrote:

>Hallo
>
>I am having following problem.
>Snort is running on the externel interface and there is also running a
>Squid Daemon on the internal interface listening on port 8080.
>The Internal Network is beeing set up as "homenetwork".
>Now everytime one of the internal Clients is surfing the net, snort
>gives me following "Scan Proxy attempt" message.
>
>Jun 16 10:49:47 *** snort: [1:620:2] SCAN Proxy (8080) attempt
>[Classification: Attempted Information Leak] [Priority: 2]: {TCP}
>192.168.181.86:50358 -> 192.168.181.222:8080
>
>Can someone tell me how to get rid of these annoying messages?
>
>Thanks in advance
>
>Marcel
>
>
>
>-------------------------------------------------------
>This SF.Net email sponsored by: Free pre-built ASP.NET sites including
>Data Reports, E-commerce, Portals, and Forums are available now.
>Download today and enter to win an XBOX or Visual Studio .NET.
>http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
>_______________________________________________
>Snort-users mailing list
>Snort-users at lists.sourceforge.net
>Go to this URL to change user options or unsubscribe:
>https://lists.sourceforge.net/lists/listinfo/snort-users
>Snort-users list archive:
>http://www.geocrawler.com/redir-sf.php3?list=snort-users
>  
>






More information about the Snort-users mailing list