Snort mailing list archives

Loopback traffic


From: "Rodrigo B. Ramos" <rodrigo.ramos () triforsec com br>
Date: Fri, 23 Apr 2004 18:05:19 -0300

Hi log watchers!!!

The big question now is "What is generating these packets?".

Following what we are seeing in the messages, I asked to my snorts to
get layer 2 informations (-e) and at the end I checked the ARP table, so
I discovered that the  "BAD-TRAFFIC loopback traffic" is coming from 
some routers interfaces and by the ttl values I could see that it comes
from some one near.

So, does anybody knows what is generating these packets?



Best regards,
-- 
Rodrigo Buarque Ramos
GPG KEY ID: 0x71CFE098 --> http://pgp.mit.edu
Key fingerprint = F381 366D D233 22B4 7E72  A21D DE9B 2FF3 71CF E098
55 81 88513524
55 81 3463.1593
http://www.triforsec.com.br
http://www.defenselayer.com

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: