Snort mailing list archives
Loopback traffic
From: "Rodrigo B. Ramos" <rodrigo.ramos () triforsec com br>
Date: Fri, 23 Apr 2004 18:05:19 -0300
Hi log watchers!!! The big question now is "What is generating these packets?". Following what we are seeing in the messages, I asked to my snorts to get layer 2 informations (-e) and at the end I checked the ARP table, so I discovered that the "BAD-TRAFFIC loopback traffic" is coming from some routers interfaces and by the ttl values I could see that it comes from some one near. So, does anybody knows what is generating these packets? Best regards, -- Rodrigo Buarque Ramos GPG KEY ID: 0x71CFE098 --> http://pgp.mit.edu Key fingerprint = F381 366D D233 22B4 7E72 A21D DE9B 2FF3 71CF E098 55 81 88513524 55 81 3463.1593 http://www.triforsec.com.br http://www.defenselayer.com
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Loopback traffic Rodrigo B. Ramos (Apr 23)
- RE: Loopback traffic Chuck Holley (Apr 23)
- RE: Loopback traffic Matt Kettler (Apr 26)
- <Possible follow-ups>
- loopback traffic Security Personnel (May 19)
- Re: loopback traffic Matt Kettler (May 19)
- Re: loopback traffic James Riden (May 19)
- Re: loopback traffic Security Personnel (May 19)
- Re: loopback traffic Matt Kettler (May 19)
- RE: loopback traffic Bob Sukovich (May 20)
- RE: Loopback traffic Chuck Holley (Apr 23)