Snort mailing list archives

Anybody been seeing this / What is it.


From: "David E. Gianndrea" <daveg () comsquared com>
Date: Thu, 27 Feb 2003 10:40:59 -0500

Does anybody know what may be causing such traffic. At one time I saw
this kind of stuff coming from one of our internal windows machines.


[**] BAD TRAFFIC udp port 0 traffic [**]
02/25-22:15:57.248993 200.140.22.177:3073 -> X.X.X.X:0
UDP TTL:112 TOS:0x0 ID:1441 IpLen:20 DgmLen:46
Len: 26
08 13 4A 49 02 00 01 00 61 62 63 64 65 66 67 68  ..JI....abcdefgh
69 6A                                            ij

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+


Thanks

--
David Gianndrea
Senior Network Engineer
Comsquared Systems, Inc.

Web:     www.comsquared.com
Email:   dgianndrea () comsquared com




-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: