Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Snort-sigs] snort_decoder T/TCP detected

From: Vincent Vono <vincent.vono(at)zurichna.com>
Date: Wed May 28 2003 - 14:15:46 EDT

Hello,

Since upgrading to snort 2.0, the following is being triggered quite often.

Generated by ACID v0.9.6b19 on Wed May 28, 2003 14:24:00


#(1 - 114829) [2003-05-28 12:48:33] (snort_decoder): T/TCP Detected IPv4: 66.21.40.101 -> 208.249.144.198

      hlen=5 TOS=0 dlen=68 ID=63195 flags=0 offset=0 TTL=52 chksum=50078 TCP: port=46341 -> dport: 80 flags=******S* seq=588727483

      ack=0 off=12 res=0 win=16384 urp=0 chksum=44986
      Options:

#1 - MSS len=2 data=0200
#2 - NOP len=0
#3 - WS len=1 data=00
#4 - NOP len=0
#5 - NOP len=0
#6 - TS len=8 data=00AA8F0B00000000
#7 - NOP len=0
#8 - NOP len=0
#9 - CCNEW len=4 data=000CB8CE

Payload: none

I've searched high and low for a solution but... Anyone have any ideas, and where in Snort can it be disabled, enabled, adjusted?

Many thanks,
Vince Vono
Zurich North America

  • PLEASE NOTE ******************* This E-Mail/telefax message and any documents accompanying this transmission may contain privileged and/or confidential information and is intended solely for the addressee(s) named above. If you are not the intended addressee/recipient, you are hereby notified that any use of, disclosure, copying, distribution, or reliance on the contents of this E-Mail/telefax information is strictly prohibited and may result in legal action against you. Please reply to the sender advising of the error in transmission and immediately delete/destroy the message and any accompanying documents. Thank you.

This SF.net email is sponsored by: ObjectStore. If flattening out C++ or Java code to make your application fit in a relational database is painful, don't do it! Check out ObjectStore. Now part of Progress Software. http://www.objectstore.net/sourceforge

Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Wed May 28 15:08:57 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:29 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library