Security Incidents mailing list archives

Re: Port 33434 and decoy-scanning


From: ryan () SECURITYFOCUS COM (Ryan Russell)
Date: Thu, 9 Mar 2000 13:45:51 -0800



Don't know the what or why but have been seeing the same traffic for
about week, same source addresses.  The source ports are the same each
pass, and occurs about the same time each day for a period of an hour or
so.  The pattern is traceroute like, generally 3 packets with TTL=1 followed
by 1 to 3 packets with TTL=2.
--

That's traceroute.

                                Ryan


Current thread: