|
|
|
|
Snort Forums Archive
Archive Home » Rules » NETBIOS SMB-DS overflow attempt
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
NETBIOS SMB-DS overflow attempt
Posted by sniglet on March 25, 2005 07:41:14
I'm seeing a large number of alerts with sid=3000 (http://www.snort.org/pub-bin/sigs.cgi?sid=3000) I'm thinking that it's innocuous traffic, but without a source to research, I can't make that determination.
Does anyone have suggestions on how to determine a false positive from a true positive? |
|
|
|
|
|