logo       

Arachnids IDS181 and interesting false positive: msg#00166

security.ids.snort.sigs

Subject: Arachnids IDS181 and interesting false positive

Hey all!

Real quick....just wanting to know what:

http://www.slave-tothe-box.net/public/acidids181.html

is....I see it come up on port 1025 as well as 135. I'm guessing it's some
expoit of some sort, but not sure which one. The false positive stems from
IDS181 rule looking at the bevy of 90 90 90 90 and seeing them as NOP's.
Thanks!

James Lay
Network Manager/Security Officer
AmeriBen Solutions/IEC Group
Deo Gloria!!!



-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise