Re: Port 0 packets

From: Andreas Östling (andreaso_at_it.su.se)
Date: 07/25/03

  • Next message: Dave Paris: "Re: Port 0 packets"
    Date: Fri, 25 Jul 2003 20:18:38 +0200 (CEST)
    To: Dave Paris <dparis@w3works.com>
    
    

    On Thu, 24 Jul 2003, Dave Paris wrote:

    > Our IDS spotted another TCP port 0 packet at 19:59pm UTC today
    > (Thursday). Headers follow:
    >
    > [**] (snort_decoder): T/TCP Detected [**]
    > 07/24-19:59:51.308749 216.136.173.246:0 -> xxx.xxx.xxx.xxx:0

    In case you don't know, snort has a bug (or had - I don't know if it has
    been fixed now) that would make those alerts generated by the snort
    decoder to always have the ports set to 0 since those values weren't yet
    assigned at that stage.
    See http://marc.theaimsgroup.com/?l=snort-devel&m=105698697005259&w=2

    /Andreas

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Dave Paris: "Re: Port 0 packets"

    Relevant Pages

    • Re: newbie quetsions (on how much Snort sucks)
      ... > I'm interested to know if you think Snort's stream reassmbler can't ... When lots of people have the same "bug" it's typically a design issue, ... But this is not a Snort bug. ... One major benefit of Open Source is that you CAN ...
      (Focus-IDS)
    • snort-1.9.0 is released!
      ... The Snort team is proud to announce the availability of version 1.9.0 ... everyone who submits bug reports and tests and submits ... Thanks for your patience and support. ... now marked as the stable branch for bug fixing and minor features ...
      (Focus-IDS)
    • Re: [SLE] Snort on 9.2
      ... > I haven't yet purchased 9.2 pro but was told Snort comes packaged with ... Check the headers for your unsubscription address For additional commands send e-mail to suse-linux-e-help@suse.com Also check the archives at http://lists.suse.com Please read the FAQs: suse-linux-e-faq@suse.com ...
      (SuSE)
    • Re: [SLE] Snort on Pro 9.1 or 9.2
      ... >> Is anyone using Snort as an NIDS. ... which rpm did you use from the ... > Check the headers for your unsubscription address ...
      (SuSE)
    • Re: 1st MPG Check
      ... some name headers from rec.motorcycles.harley ... on being the group's Net Nanny, ... WTF??? ...
      (rec.motorcycles.harley)