On Friday 18 January 2002 02:37 pm, Craig Van Tassle wrote:
> Im getting some alerts from a ip that we all know and love.
> Security Focus.  Has any one gotten the same results or has any ides on why
> this would be happening?
>
> Thnaks
>
> Craig
>
> P.S. here is the output from my snort logs
> [**] ATTACK RESPONSES id check returned root [**]
> 01/18-04:21:58.569692 66.38.151.27:53886 -> x.x.x.x:25
> TCP TTL:42 TOS:0x0 ID:57084 IpLen:20 DgmLen:1500 DF
> ***A**** Seq: 0x8F3CCC0C  Ack: 0xA7DB1015  Win: 0x16D0  TcpLen: 32
> TCP Options (3) => NOP NOP TS: 669129608 27111348
> =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
sometimes when viewing pages or getting email that contain information on 
suspicious traffic will trigger alerts (tcpdump logs do this the most)


Reply via email to