Snort mailing list archives

Strange traffic?


From: Vjay LaRosa <vjayl () emc com>
Date: Wed, 26 Sep 2001 10:57:20 -0400

Hello,

Can some one help me here. I can't think of any reason that I would be
seeing this traffic.

09/26-09:10:17.709508  [**] [1:0:0] TFTP Traffic [**] [Classification:
Potentially Bad Traffic] [Priority: 2] {UDP} X.X.X.X:53 -> X.X.X.X:69

Why would there be a TFTP session using the source port for DNS? Any
ideas would be appreciated. Thanks!

vjl

--
 V.Jay LaRosa                           EMC Corporation
 Systems Administrator                  171 South Street
 (508)435-1000 ext 14957                Hopkinton, MA 01748
 (508)497-8082 fax                      www.emc.com



Current thread: