Firewall Wizards mailing list archives
TCP 4885 to 0's broadcast address
From: <epperson () vak12ed edu>
Date: Thu, 14 Nov 2002 13:54:52 EST
We're seeing traffic targeting the 0's broadcast address on one of our subnets (e.g. 10.1.1.0) mostly with a dest port of UDP 4885 (a few are bound for TCP 4881). Sources tend to be a stream of various addresses within a 16-bit prefix, then it switches to another 16-bit prefix. Have not been able to identify this pattern as to intent, although we're picking them off. Does anyone recognize this footprint? regards, j. _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- TCP 4885 to 0's broadcast address epperson (Nov 14)