Snort mailing list archives

[off topic] poor firewall (was Re: Strange traffic?)


From: "Bruno Gimenes Pereti" <pereti () ump edu br>
Date: Wed, 26 Sep 2001 13:25:20 -0300

Looks like someone is trying to scan your net for TFTP servers.  Using a
source port of 53 is a common method to bypass poorly configured
firewalls.

Hi,

I know it is not directly relationed to snort but I got worried when Erek
mensioned "poor configured firewalls".
Where could I find some information about *GOOD* IPChains rules and what
exploit are they for.

Thank's and sorry for the off topic.

Bruno Gimenes Pereti.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: