Snort mailing list archives

How do I stop the following


From: "Trevor and Cindy" <maingot () attglobal net>
Date: Fri, 21 Dec 2001 06:38:22 -0800

Hi,
 
A Snort newbie here.  I was wondering what the following alert is and
how do I stop it, I sure hope it is a false positive since I get
thousands of them a day which really bogs down snortsnarf.  The strange
thing is I do not see the IP addresses that cause these things showing
up on the firewall logs.
 
[**] [1:515:2] MISC source port 53 to <1024 [**]
[Classification: Potentially Bad Traffic] [Priority: 2]
12/17-08:11:00.311810 216.115.108.33:53 -> 63.168.165.253:53
UDP TTL:53 TOS:0x0 ID:9702 IpLen:20 DgmLen:517
Len: 497
 
I have been looking through the mailing list, but have not seen anything
that shows how to stop this.  Any help would be greatly appreciated.
 
Thanks
 
Trevor 

Current thread: