[Snort-users] Interesting entries in BASE

CasperLinux CasperLinux at ...5068...
Sun Feb 26 16:25:07 EST 2006


On Sunday 26 February 2006 18:59, you wrote:
> That entry is from the sfportscan preprocessor.  You can enable,
> tune, or disable this preprocessor via your snort.conf

Ok but why did it suddenly decide to kick itself on? I have had every rule 
turned on for the better part of a week and this is the first day I noticed 
it.  

I did a check and I have three hits on a portscan (1 Saturday and 2 today) and 
15 open port checks (all today in about a 2 minute timeframe).

This seems to be something that got triggered somehow.
>
> Joel

Don

- Powered by Debian Linux - 




More information about the Snort-users mailing list