[Snort-users] snort_decoder

MH procana at ...4296...
Fri May 2 04:00:07 EDT 2003


Hi Brian,

It is not an error.

Check out post: 
http://marc.theaimsgroup.com/?l=snort-users&m=105183409225588&w=2

FYI: The CCNEW option is triggering this alert.

Hope this helps,
Mike




At 04:00 PM 5/1/2003 -0700, Bryan Irvine wrote:
>Does this look familiar to anyone?
>What kind of error is this?  I can't find it in the rules anywhere, so I
>assume it's coming directly from snort somehow.
>
>
>
>[**] [116:56:1] (snort_decoder): T/TCP Detected [**]
>05/01-15:01:41.513461 205.229.151.150:0 -> 64.1.201.147:0
>TCP TTL:49 TOS:0x0 ID:50137 IpLen:20 DgmLen:68
>******S* Seq: 0x839CCEA2  Ack: 0x0  Win: 0x4000  TcpLen: 48
>TCP Options (9) => MSS: 512 NOP WS: 0 NOP NOP TS: 9875582 0 NOP
>TCP Options => NOP CCNEW: 923253
>
>
>
>--Bryan
>
>





More information about the Snort-users mailing list