Snort mailing list archives

UUnet dns server portscans filling up log.. causing email of real alerts to crash


From: "Madhav Diwan" <mdiwan () wagweb com>
Date: Wed, 11 Jul 2001 09:52:26 -0400

Hey guys.. how do i stop this message from getting into secure log?

Jul 11 09:25:24 FG-IDS1 snort[595]: spp_portscan: portscan status from
198.6.1.5: 1 connections across 1 hosts: TCP(0), UDP(1)

the address is that of a uunet dns server , .. this address is in the
snort.conf file for the portscan ignore .. but it doesn't seem to help:

var DNS_SERVERS [198.6.1.5/32,198.6.1.1/32]

preprocessor portscan-ignorehosts: $DNS_SERVERS

snort has been restarted but still logs these scans.

does the netmask have to be present for this to work ? I am not certain
that this is the netmask of the uunet servers .. how do i find out what
that is?

this is filling up my secure log and causing my email of alerts to crash

thanks 

madhav


____________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Note: The information contained in this message may be privileged and confidential and protected from disclosure.  If 
the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this 
message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this 
communication is strictly prohibited. If you have received this communication in error, please notify us immediately by 
replying to the message and deleting it from your computer.  Thank you.  Wagner Weber & Williams

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: