Every hour I get these alerts which I believe are false positives. They seem to coincide with a user's mobile phone connecting via owa. Anybody else seeing this?
-------------------------
Intrusion Protection Alert
An intrusion has been detected. The packet has been dropped automatically.
You can toggle this rule between "drop" and "alert only" in WebAdmin.
Details about the intrusion alert:
Message........: WEB-MISC PCT Client_Hello overflow attempt
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=2515
Time...........: 2008:09:09-11:34:43
Packet dropped.: yes
Priority.......: 1 (high)
Classification.: Attempted Administrator Privilege Gain IP protocol....: 6 (TCP)
-------------------------
Not causing an issue with the user getting email just a dozen irritating notices every hour. Is there any way to stop alerts for this particular alert without disabling the entire group/category? In version 6 you could configure individual alerts within a category, it seems as though that functionality has been removed in version 7.30.
thanks,
Patrick
This thread was automatically locked due to age.