[Snort-users] snort_decoder

Bryan Irvine bryan.irvine at ...9066...
Thu May 1 15:59:08 EDT 2003


Does this look familiar to anyone?
What kind of error is this?  I can't find it in the rules anywhere, so I
assume it's coming directly from snort somehow.



[**] [116:56:1] (snort_decoder): T/TCP Detected [**]
05/01-15:01:41.513461 205.229.151.150:0 -> 64.1.201.147:0
TCP TTL:49 TOS:0x0 ID:50137 IpLen:20 DgmLen:68
******S* Seq: 0x839CCEA2  Ack: 0x0  Win: 0x4000  TcpLen: 48
TCP Options (9) => MSS: 512 NOP WS: 0 NOP NOP TS: 9875582 0 NOP 
TCP Options => NOP CCNEW: 923253 



--Bryan





More information about the Snort-users mailing list