Snort mailing list archives

Re: snort alert


From: Joerg Weber <j.weber () infos de>
Date: 16 Sep 2003 09:26:14 +0200

Hi,

Hello!!!
In snort alert I see this lines :

[**] SCAN UPNP service discover attempt [**]
09/15-16:39:10.579722 172.19.1.79:1198 -> 239.255.255.250:1900
UDP TTL:4 TOS:0x0 ID:16768 IpLen:20 DgmLen:161
Len: 133

What they mean and where I can read about it?
Thank for any help.

I'm sure you just forgot to look into the archives, so here's a link:

http://marc.theaimsgroup.com/?l=snort-users&w=2&r=1&s=scan+upnp&q=b

Cheers,

Joerg

-- 
Joerg Weber
Network Security

infoServe GmbH
Nell-Breuning-Allee 6
D-66115 Saarbruecken

T: (0681) 8 80 08 - 0
F: (0681) 8 80 08 - 33
www.infos.de
E: j.weber () infos de

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: