[Snort-users] Wrong rule's signature for "MS-SQL Worm propagation attempt"

Joshua Berry jberry at ...11848...
Wed Jul 28 06:57:01 EDT 2004

I believe this is a known problem of a previous version of Snort, what
version are you running?

-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Phong
Sent: Wednesday, July 28, 2004 8:09 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Wrong rule's signature for "MS-SQL Worm
propagation attempt"

Hello all,

I'm facing a problem that I cannot resolved by myself. My snort is
"MS-SQL Worm propagation attempt" alerts but wich are in fact "ICMP
Quench" alerts !!! I'm sure of that because when I look to the alert, it

shows me a ICMP request (type 4).

Because my firewall is blocking IP address when a "MS-SQL Worm
attempt" alert is detected, so are some IP address wrongly blocked when
sent ICMP Source Quench !! 

Could somebody help me please
Thanks a lot

Nguyen Phong
Axone Services & Developments
2 crs de Rive
1204 GE/CH

This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list