[Snort-users] bad IP traffic
operator at ...7874...
Wed Jun 11 05:54:02 EDT 2003
My company NIDS - i.e. snort 2.0 - is triggering since three/four days a lot
of "BAD-TRAFFIC bad frag bits" alerts.
These come out when a TCP packet has both fragment and don't_fragment bit
Target of these alerts is almost always the IP address of a particular Web
Server (one of our server farm).
Other alerts are triggered on this target, some are common ones such as
Apache worm for Apache old version but this
is a usual maltraffic, but other ones are of type "bad TCP/IP traffic", such
as anomalous TTL values for packets.
It seems to me this could be a scan/gathering info technique, is it correct?
can this be a False Positive ? Can this
be something more dangerous?
Any help will be very appreciated,
Lines below are "the price to pay" for a free service of a commercial
Email.it, the professional e-mail, gratis per te: http://www.email.it/f
Viaggiare in aereo spendendo poco non h un sogno perchh Sterling fa dei tuoi sogni realt`, clicca subito
Clicca qui: http://adv.email.it/cgi-bin/foclick.cgi?mid=1227&d=11-6
More information about the Snort-users