Snort mailing list archives
Re: snort alert
From: Joerg Weber <j.weber () infos de>
Date: 16 Sep 2003 09:26:14 +0200
Hi,
Hello!!! In snort alert I see this lines : [**] SCAN UPNP service discover attempt [**] 09/15-16:39:10.579722 172.19.1.79:1198 -> 239.255.255.250:1900 UDP TTL:4 TOS:0x0 ID:16768 IpLen:20 DgmLen:161 Len: 133 What they mean and where I can read about it? Thank for any help.
I'm sure you just forgot to look into the archives, so here's a link: http://marc.theaimsgroup.com/?l=snort-users&w=2&r=1&s=scan+upnp&q=b Cheers, Joerg -- Joerg Weber Network Security infoServe GmbH Nell-Breuning-Allee 6 D-66115 Saarbruecken T: (0681) 8 80 08 - 0 F: (0681) 8 80 08 - 33 www.infos.de E: j.weber () infos de
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- snort alert Владимир Потапов (Sep 15)
- Re: snort alert Joerg Weber (Sep 16)
- <Possible follow-ups>
- snort alert Vladimir Potapov (Sep 16)