Gatt Posted May 18, 2013 Posted May 18, 2013 LAst few times I've visited EduGeek @ Home, Sophos UTM 9 sends me a half dozen IPS Alerts similiar to this... Intrusion Prevention Alert An intrusion has been detected. The packet has been dropped automatically. You can toggle this rule between "drop" and "alert only" in WebAdmin. Details about the intrusion alert: Message........: MALWARE-OTHER HTTP POST request to a JPG file Details........: Snort :: Time...........: 2013-05-18 14:11:18 Packet dropped.: yes Priority.......: medium Classification.: Detection of a non-standard protocol or event IP protocol....: 6 (TCP) Source IP address: 192.168.0.4 (proxy) - Professional Toolset | DNSstuff - Database Query - http://ws.arin.net/cgi-bin/whois.pl?queryinput=192.168.0.4 - APNIC - Query the APNIC Whois Database Source port: 49989 Destination IP address: 78.47.226.90 (www.edugeek.net) - Professional Toolset | DNSstuff - Database Query - http://ws.arin.net/cgi-bin/whois.pl?queryinput=78.47.226.90 - APNIC - Query the APNIC Whois Database Destination port: 80 (http) -- System Uptime : 4 days 6 hours 21 minutes System Load : 0.39 System Version : Sophos UTM 9.100-16 Please refer to the manual for detailed instructions. It seems to not be liking something coming back on TCP Port 6
ZeroHour Posted May 21, 2013 Posted May 21, 2013 Hmmm not sure as we dont host anything on port 6 (its firewalled as well) 1
tom_newton Posted May 21, 2013 Posted May 21, 2013 It looks more likely that it's the "Post request to a jpg" (which seems reasonably kosher to me) rule that's causing the issue - I suspect you will find some missing images in edugeek - almost certainly a dynamically generated one. I suggest you disable the rule, it seems a bit OTT 1
SimonD Posted May 21, 2013 Posted May 21, 2013 Also that's protocol 6 (TCP) not Port 6 you are for sure using this on port 80 at least 1
tom_newton Posted May 21, 2013 Posted May 21, 2013 Hey we're all buddies together on here, right? Guy in the pic reminds me of Gav for some reason.... ;-P 1
Gatt Posted May 21, 2013 Author Posted May 21, 2013 Thanks for the info, I've already turned off one IPS rule after it spammed me for having BitTorrent running! (25 alerts per second isn't good!) I'll shut this one off too...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now