Here is the ACID Log:
#0-(1-5296) [snort] ATTACK-RESPONSES id check returned
userid 2003-05-22 15:27:20 192.168.2.8:25 204.92.158.14:40095 TCP
#2-(1-5291) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:43 192.168.2.8:4243 206.24.192.154:80 TCP
#3-(1-5290) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:40 192.168.2.8:4250 206.24.192.154:80 TCP
#4-(1-5289) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:39 192.168.2.8:4249 206.24.192.154:80 TCP
#5-(1-5286) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:38 192.168.2.8:4246 206.24.192.154:80 TCP
#6-(1-5287) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:38 192.168.2.8:4247 206.24.192.154:80 TCP
#7-(1-5288) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:38 192.168.2.8:4248 206.24.192.154:80 TCP
#8-(1-5285) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:36 192.168.2.8:4245 206.24.192.154:80 TCP
#9-(1-5283) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:35 192.168.2.8:4242 206.24.192.154:80 TCP
#10-(1-5284) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:35 192.168.2.8:4244 206.24.192.154:80 TCP
#11-(1-5282) [snort] ATTACK-RESPONSES id check returned userid 2003-05-22 15:15:33 192.168.2.8:4241 206.24.192.154:80 TCP
#12-(1-527
The message "ATTACK-RESPONSES id check returned userid" appears in ACID log every couple minutes.
192.168.2.8 is e-smith external interface.
Is anybody know how to check and clean up my E-smith box?
E-smirh 5.1.2, SNORT, ACID v0.9.6b23