|
|
|
|
Snort Forums Archive
Archive Home » Support » Question about snort alert log
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Question about snort alert log
Posted by _Slivix_ on March 28, 2005 13:16:00
I have snort 2.2 with the lastest rules and occasionally I will get a slew of http_inspect alerts (OVERSIZE CHUNK ENCODING, APACHE WHITESPACE (TAB), BARE BYTE UNICODE ENCODING, NON-RFC HTTP DELIMITER, OVERSIZE REQUEST-URI DIRECTORY).
Here's the issue: The target ips in the logs for these http_inspect alerts are not on my machine. e.g., 03/28-14:08:56.492734 [**] [119:12:1] (http_inspect) APACHE WHITESPACE (TAB) [**] {TCP} some.ip.number.outthere:4140 -> not.on.my.machine:80
The targeted machines are close by (behind the same router) and it only happens for some of the http inspect alerts.
Any clues or links would be appreciated.
Thanks!
|
|
|
|
|
|