|
|||||||||||
|
[Snort-sigs] spp_stream4 Steath activity
From: John Hally <JHally(at)epnet.com>
Date: Fri May 30 2003 - 14:36:49 EDT I'm seeing a good amount of these alerts coming from the stream4 preprocessor. For the most part the payload of the packets look normal, but they all have ACK,PUSH,RST set. Has anyone else seen this behavior? The traffic is originating from a proxy of some sort and destined for an 2000/IIS5 server, if that helps. John H. This SF.net email is sponsored by: eBay Get office equipment for less on eBay! http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5 Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Fri May 30 15:26:20 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:29 EDT |
||||||||||
|
|||||||||||