Firewall Wizards mailing list archives

TCP 4885 to 0's broadcast address


From: <epperson () vak12ed edu>
Date: Thu, 14 Nov 2002 13:54:52 EST

We're seeing traffic targeting the 0's broadcast address on one of our
subnets (e.g. 10.1.1.0) mostly with a dest port of UDP 4885 (a few are bound
for TCP 4881).  Sources tend to be a stream of various addresses within a
16-bit prefix, then it switches to another 16-bit prefix.  Have not been able
to identify this pattern as to intent, although we're picking them off.

Does anyone recognize this footprint?

regards,
j.
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: