HIPS activity logs is (sometimes) showing a blocked incoming data before the incoming connection is fully established
I've been experimenting some weird problem with the log generated by McAfee HIPS. I wrote a quick python script that perform 100 requests to a website and for some reason that I don't understand, I see "blocked incoming traffic" even if the connection is not yet established !
I've uninstalled the Microsoft QoS driver from the wireless card just in case that it was interfering with the packet order ... and fire up Wireshark to see if my script was doing anything weird but all requests are made exactly the same way.
I'm using McAfee HIPS 126.96.36.19961 build 2919.
Any ideas why it's causing this ? Is there a patch available ?
Is it a false positive ? It looks like it is, the data is received even if it's written has blocked.