S
SherryB
Event Type: Information
Event Source: snort
Event Category: None
Event ID: 1
Date: 10/4/2004
Time: 3:15:27 PM
User: N/A
Computer: XXX
Description:
[1:466:1] ICMP L3retriever Ping [Classification: Attempted Information Leak]
[Priority: 2]: {ICMP} 192.168.1.20 -> 192.168.1.15
..20 is my workstation, and .15 is my domain controller (W2Ksvr). I
seriously doubt that my workstation is leaking any new information to my
domain controller. What does this mean and how can I make it stop filling
up my Application Log with these things?
Thanks!
Event Source: snort
Event Category: None
Event ID: 1
Date: 10/4/2004
Time: 3:15:27 PM
User: N/A
Computer: XXX
Description:
[1:466:1] ICMP L3retriever Ping [Classification: Attempted Information Leak]
[Priority: 2]: {ICMP} 192.168.1.20 -> 192.168.1.15
..20 is my workstation, and .15 is my domain controller (W2Ksvr). I
seriously doubt that my workstation is leaking any new information to my
domain controller. What does this mean and how can I make it stop filling
up my Application Log with these things?
Thanks!