[Snort-users] Wrong rule's signature for "MS-SQL Worm propagation attempt"
jberry at ...11848...
Wed Jul 28 06:57:01 EDT 2004
I believe this is a known problem of a previous version of Snort, what
version are you running?
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Phong
Sent: Wednesday, July 28, 2004 8:09 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Wrong rule's signature for "MS-SQL Worm
I'm facing a problem that I cannot resolved by myself. My snort is
"MS-SQL Worm propagation attempt" alerts but wich are in fact "ICMP
Quench" alerts !!! I'm sure of that because when I look to the alert, it
shows me a ICMP request (type 4).
Because my firewall is blocking IP address when a "MS-SQL Worm
attempt" alert is detected, so are some IP address wrongly blocked when
sent ICMP Source Quench !!
Could somebody help me please
Thanks a lot
Axone Services & Developments
2 crs de Rive
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users