This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange IPS detection v6.004

Since 2 weeks ago i'm getting everyday a ton of these hits:

Message........: SHELLCODE x86 NOOP
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=1394
Time...........: 2005:09:26-12:25:24
Packet dropped.: yes
Priority.......: 1 (high)
Classification.: Executable code was detected IP protocol....: 6 (TCP)

Source IP address: [Astaro internal IP address] (hostname)
Source port: 8080 (http-alt)
Destination IP address: [one of the PC in the LAN]
Destination port: 2206

how can i be getting these kind of packets originating in the http proxy of astaro?
what might be causing them?


This thread was automatically locked due to age.
Parents
  • Hi, 

    most likely, someone in your local network ist using the proxy to make a request to a system on your local network. 
    Mostly this comes from not using the, "don't use proxy for local network" features of the browsers. 

    Chris
Reply
  • Hi, 

    most likely, someone in your local network ist using the proxy to make a request to a system on your local network. 
    Mostly this comes from not using the, "don't use proxy for local network" features of the browsers. 

    Chris
Children
No Data