Snort mailing list archives
Re: spp
From: Joe McAlerney <joey () SiliconDefense com>
Date: Mon, 02 Jul 2001 16:05:51 -0700
Hello, Try adding /32 netmasks to those addresses: var DNS_SERVERS [xxx.xx.0.3/32,xxx.xxx.0.2/32] And make sure the $DNS_SERVERS variable is on the portscan-ignorehosts line: preprocessor portscan-ignorehosts: $DNS_SERVERS Lastly, are "stealth" packets being detected? If so, see this FAQ. http://www.snort.org/FAQ.html#q13 HTH, -Joe M. -- | Joe McAlerney joey () silicondefense com | | Silicon Defense - Technical Support for Snort | | http://www.silicondefense.com/ | +-- --+ niko () digitalenigma com wrote:
I am still getting bombarded with spp_portscan messages even though the IP that I am getting the portscan from is in my $DNS_SERVERs var Here is a modified snippet: var DNS_SERVERS [xxx.xx.0.3,xxx.xx.0.2] The .0.2 is the one I am still receiving. Any ideas?? _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: spp Joe McAlerney (Jul 02)
