OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Snort-users] SCAN Proxy (8080) attempt

From: Marcel (error79gmx.de)
Date: Sun Jul 06 2003 - 12:09:56 CDT


Hallo

I am having following problem.
Snort is running on the externel interface and there is also running a
Squid Daemon on the internal interface listening on port 8080.
The Internal Network is beeing set up as "homenetwork".
Now everytime one of the internal Clients is surfing the net, snort
gives me following "Scan Proxy attempt" message.

Jun 16 10:49:47 *** snort: [1:620:2] SCAN Proxy (8080) attempt
[Classification: Attempted Information Leak] [Priority: 2]: {TCP}
192.168.181.86:50358 -> 192.168.181.222:8080

Can someone tell me how to get rid of these annoying messages?

Thanks in advance

Marcel

-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users