Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.13 What about ``CGI Up: 4 Rules and Alerts Previous: 4.11 What are these

4.12 Snort says BACKDOOR SIGNATURE... does my machine have a Trojan?

If you are dumping the data part of the packet, review it. These rules are known to have high false rates as most of them are just based on numeric port numbers.