Security Incidents mailing list archives

UDP Port 9 - "play" (tcpdump included)


From: Golden_Eternity <bhodi () BIGFOOT COM>
Date: Mon, 26 Mar 2001 12:37:05 -0800

I've been getting connections like this for weeks... anyone know what this
might be?

All the packets I logged had that "play" message.

17:41:36.130000 someaddress.myisp.com.3160 > 255.255.255.255.discard:  udp
52 (ttl 128, id 49183, len 80)
0x0000   4500 0050 c01f 0000 8011 ad26 cfaf fda7        E..P.......&....
0x0010   ffff ffff 0c58 0009 003c 87b2 3400 b0fa        .....X...<..4...
0x0020   0200 0937 0000 0000 0000 0000 96ff a89a        ...7............
0x0030   706c 6179 0200                                 play..


Current thread: