Security Incidents mailing list archives

Re: Big traffic on 412/tcp


From: Ian Stoba <ian () babcockbrown com>
Date: Wed, 24 Apr 2002 09:20:29 -0700

It appears to be used by the Direct Connect peer to peer file sharing program:

http://www.dac.neu.edu/dac/hdesk/pip0202.pdf

(Google is your friend!)

Cheers,

--Ian

On Wednesday, April 24, 2002, at 01:43  AM, Guido Van De Velde wrote:

We see here in our Cisco netflow data quite a large amount of data coming from 412/tcp (about 20 gbyte/day, about 1/8 of our http data). It seem to me that the official use, synoptics-trap, isn't that used, or am I wrong.

Does anyone know what they transport on this port ?



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com


Current thread: