LoFP LoFP / t1189

t1189

TitleTags
internal vulnerability scanners can cause some serious fps when used, if you experience a lot of fps due to this think of adding more filters such as \"user agent\" strings and more response codes
javascripts,css files and png files
legitimate browser install, update and recovery scripts
split-horizon dns, vpn transitions, service discovery, failover, hairpin nat, and dual-stack names that publish a public a record with a unique-local aaaa record can legitimately produce public and private answers for the same name. recursive resolvers, dns forwarders, and localhost listeners can also aggregate many endpoints under one client address. security products may sinkhole suspicious domains to loopback or private addresses with short ttls. confirm the domain, resolver placement, and client identity before adding an exception, and scope exceptions by registered domain or client rather than globally.
unknown flash download locations
user searches in search boxes of the respective website
web activity that occurs rarely in small quantities can trigger this alert. possible examples are browsing technical support or vendor urls that are used very sparsely. a user who visits a new and unique web destination may trigger this alert when the activity is sparse. web applications that generate urls unique to a transaction may trigger this when they are used sparsely. web domains can be excluded in cases such as these.