Snort mailing list archives
How do I stop the following
From: "Trevor and Cindy" <maingot () attglobal net>
Date: Fri, 21 Dec 2001 06:38:22 -0800
Hi, A Snort newbie here. I was wondering what the following alert is and how do I stop it, I sure hope it is a false positive since I get thousands of them a day which really bogs down snortsnarf. The strange thing is I do not see the IP addresses that cause these things showing up on the firewall logs. [**] [1:515:2] MISC source port 53 to <1024 [**] [Classification: Potentially Bad Traffic] [Priority: 2] 12/17-08:11:00.311810 216.115.108.33:53 -> 63.168.165.253:53 UDP TTL:53 TOS:0x0 ID:9702 IpLen:20 DgmLen:517 Len: 497 I have been looking through the mailing list, but have not seen anything that shows how to stop this. Any help would be greatly appreciated. Thanks Trevor
Current thread:
- How do I stop the following Trevor and Cindy (Dec 21)
- Re: How do I stop the following Phil Wood (Dec 23)
