[Snort-users] SQUID scan proxy attempt

Fabio Viero fviero at ...9913...
Tue Feb 24 06:59:28 EST 2004


Hi

I'm new to snort and i had setup a very simple test configuration. In short, i run squid on 192.168.0.1 (and apache, snort with acid and so on...) and i have a win98(192.168.0.2) client that access the internet via this proxy server (192.168.0.1). Snort is detecting this access (from 192.168.0.2 to 192.168.0.1) as a "SCAN squid proxy attempt". We know it's not what's really happening. The server 192.168.0.1 has no firewall rules. The only access control is done with squid.

Could anyone give an insight about this problem?

Thanks in advance to anyone of you.

-----------------------------------------
"A day without Linux is day
without learning."
-----------------------------------------




More information about the Snort-users mailing list