TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Large amount of same event came from our RealSecure 5.0 network sensor. I
think below signatures are "False Positive"
signatures.

-TFN2000(It seems that this attack originates from our servers, but actually
not)
- SYNFlood( With default setting lots of this event)
-TCP_Overlap_Data

regards,

Faruk





-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Marc Class
Sent: Tuesday, August 29, 2000 1:56 AM
To: [EMAIL PROTECTED]
Subject: TCP_Overlap_Data



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Hi all

I ran this one by ISS but did not get the answer I wanted so I thought I
would
put it to the rest of you.

Since upgrading from RS3.2 to RS5.0 we have seen a huge jump in the amount
of
TCP_Overlap_Data events.

In the past months we used to get about 10 - 20 a day and since upgrading to
v5 we have been getting 4000 PLUS a day.

I posted this to ISS but got a description of the signature (Thanks)....
What
I really want to know is if this is a bug in v5 or just a coincidence.

We are running v5.0 with Xpress updates 1 and 2.

Is anyone else getting similar figures?

Thanks

MARC CLASS

MNET Australia Pty. Ltd.
Melbourne - Beautiful one day Overcast the next
Australia
[EMAIL PROTECTED]






Reply via email to