Security Incidents mailing list archives

discard 9/udp sink null


From: Golden_Eternity <bhodi () BIGFOOT COM>
Date: Thu, 15 Mar 2001 03:25:48 -0800

I've been seeing hits to udp port 9 at random intervals over the last few
days. Any idea what this might be?

The source is from within the same isp, but is not in the same subnet as I
am,  so I guess there's probably an additional issue with my isp routing
broadcast traffic...

Mar 14 23:31:44 roto-router kernel: Packet log: input DENY eth1 PROTO=17
xxx.xxx.xxx.xxx:3067 255.255.255.255:9 L=80 S=0x00 I=39420 F=0x0000 T=128
(#9)


Current thread: