I had Excepted my laptop from IPS, but decided to submit it to the checks. This is the only Alert I get. Normally, there's nothing, then there will be a burst of about 15. I only connect via VPN to our Astaro. The server is our SBS2003 running Exchange, AD, DHCP, DNS, etc. My laptop is Vista Pro SP1.
Message........: EXPLOIT kerberos principal name overflow TCP
Details........: http://www.snort.org/pub-bin/sigs.cgi?sid=2579
Time...........: 2009:06:01-10:16:01
Packet dropped.: yes
Priority.......: 1 (high)
Classification.: Attempted Administrator Privilege Gain
IP protocol....: 6 (TCP)
Source IP address: 10.x.x.51
Source port: 18345
Destination IP address: 10.x.x.7 (server.company.local)
Destination port: 88 (kerberos)
Cheers - Bob
This thread was automatically locked due to age.