Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » NETBIOS SMB-DS overflow attempt

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

NETBIOS SMB-DS overflow attempt


Posted by sniglet on March 25, 2005 07:41:14

I'm seeing a large number of alerts with sid=3000 (http://www.snort.org/pub-bin/sigs.cgi?sid=3000) I'm thinking that it's innocuous traffic, but without a source to research, I can't make that determination.

Does anyone have suggestions on how to determine a false positive from a true positive?