Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS False Positive ?

Started getting these last night (Tuesday night we do patching).

Intrusion Prevention Alert

 

An intrusion has been detected. The packet has been dropped automatically.

You can toggle this rule between "drop" and "alert only" in WebAdmin.

 

Details about the intrusion alert:

 

Message........: FILE-OTHER Interactive Data eSignal stack buffer overflow attempt

Details........: https://www.snort.org/search?query=20842

Time...........: 2021-12-08 12:17:32

Packet dropped.: yes

Priority.......: high

Classification.: Attempted User Privilege Gain IP protocol....: 6 (TCP)

 

Source IP address: 23.44.205.162 (a23-44-205-162.deploy.static.akamaitechnologies.com)

Source port: 80 (http)

Destination IP address: 192.168.xx.xx (Barcode3.mynetwork.local) Destination port: 56932



This thread was automatically locked due to age.
Parents Reply Children
No Data