This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange IPS detection v6.004

Since 2 weeks ago i'm getting everyday a ton of these hits:

Message........: SHELLCODE x86 NOOP
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=1394
Time...........: 2005:09:26-12:25:24
Packet dropped.: yes
Priority.......: 1 (high)
Classification.: Executable code was detected IP protocol....: 6 (TCP)

Source IP address: [Astaro internal IP address] (hostname)
Source port: 8080 (http-alt)
Destination IP address: [one of the PC in the LAN]
Destination port: 2206

how can i be getting these kind of packets originating in the http proxy of astaro?
what might be causing them?


This thread was automatically locked due to age.
Parents
  • Shellcode IPS rules are very prone to false positives, particularly with downloads from HTTP and FTP Sites... I've had to disable that whole category myself.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • Shellcode IPS rules are very prone to false positives, particularly with downloads from HTTP and FTP Sites... I've had to disable that whole category myself.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data