[suse-security] snort going mad, portscan against myself?
Hi together! I just figured out how to run snort (altough it doesn't start at boot-up, hell knows why...). Now it keeps telling me, that there is a portscan against myself from my machine running. Look at this: [**] [100:1:1] spp_portscan: PORTSCAN DETECTED from 10.0.3.19 (THRESHOLD 4 connections exceeded in 7 seconds) [**] 09/24-23:52:42.477424 [**] [100:2:1] spp_portscan: portscan status from 10.0.3.19: 6 connections across 6 hosts: TCP(5), UDP(1) [**] 09/24-23:53:58.678712 [**] [100:2:1] spp_portscan: portscan status from 10.0.3.19: 1 connections across 1 hosts: TCP(0), UDP(1) [**] 09/24-23:54:03.679551 [**] [100:2:1] spp_portscan: portscan status from 10.0.3.19: 1 connections across 1 hosts: TCP(0), UDP(1) [**] 09/24-23:54:08.689307 [**] [100:2:1] spp_portscan: portscan status from 10.0.3.19: 2 connections across 2 hosts: TCP(1), UDP(1) [**] 09/24-23:55:00.534798 And I swear, I'm not running any nmap or anything similar, and haven't been running since the last reboot... Could anybody help me please? TIA kind regards markus
* Markus Kohli wrote on Mon, Sep 24, 2001 at 23:59 +0200:
[**] [100:2:1] spp_portscan: portscan status from 10.0.3.19: 1 connections across 1 hosts: TCP(0), UDP(1) [**] 09/24-23:54:03.679551
Well, I think a trigger of 1 connection is a little bit small for a portscan - I wonder why not all requests are reported as portscan. Check log to what hosts those packages go - if they go to internal host, you might have snort installed on the wrong interface :) snort.conf: preprocessor portscan: $HOME_NET 4 3 portscan.log 4 conns in 3 seconds, you could increase the values. But usually a router shouldn't make connections to $HOME_NET. Maybe snort is right but your configuration is wrong? tcpdump a little, check what your gateway tries to do. Check your $HOME_NET, maybe it's wrong configured (wrong netmask or whatver). oki, Steffen -- Dieses Schreiben wurde maschinell erstellt, es trägt daher weder Unterschrift noch Siegel.
participants (2)
-
Markus Kohli
-
Steffen Dettmer