[Snort-users] Snort_decoder question

Hobgood, Frankie Frankie.Hobgood at ...8808...
Mon May 19 11:23:09 EDT 2003


I am seeing a large amount of alerts like the one below every day.  Both
addresses are internal address.  What line in the snort.conf file under the
snort decoder config do I need to uncomment to stop seeing these?

(snort_decoder): Short UDP packet, length field > payload length {UDP}
xxx.xxx.xxx.xxx:0 -> xxx.xxx.xxx.xxx:0

Thanks,
Frank Hobgood CCNA, NNCDS, SCP
Network Analyst II 
DSM Pharmaceuticals, Inc.
frankie.hobgood at ...8806...


This e-mail is for the intended recipient only.
If you have received it by mistake please let us know by reply and then
delete it from your system; access, disclosure, copying, distribution or
reliance on any of it by anyone else is prohibited.
If you as intended recipient have received this e-mail incorrectly, please
notify the sender (via e-mail) immediately.




More information about the Snort-users mailing list