[Dshield] Need help with this pattern

Chan, Stephen (TIS, Singapore) stephen_chan at sg.ml.com
Thu Oct 25 03:14:14 GMT 2001


Hi people, this is an excerpt of a Snort log I have placed outside my
firewall. 

 <<...OLE_Obj...>> 

It seems to be a bunch of spoofed source IP hitting my IDS host
(aa.bb.cc.dd). The actual trace runs over 3 days! with similar patterns. Has
anyone else seen anything like this? Or do you need more information?





More information about the list mailing list