Snort mailing list archives

udp port 0 attempts and portscan to port 0


From: "Tudor Panaitescu" <tpanaitescu () colorcon com>
Date: Thu, 13 Mar 2003 10:11:20 -0500





Hi everyone,

I see an increase in udp port 0 connection attempts to my systems here, also
portscans to port 0 (reported in both alerts and portscan.log). For portscans I
have just <source IP>:0 -> <destination IP>:0 NULL *******

Do you know what is this all about ?

I ran a tcpdump capture (ethereal) yesterday to see if there were any port 0
connections there but all I saw were just some fragmented packets. I am running
1.8.7 on RH7.2 with flexresp.

Any light on this would be highly appreciated.

TIA,
Tudor





-------------------------------------------------------
This SF.net email is sponsored by:Crypto Challenge is now open! 
Get cracking and register here for some mind boggling fun and 
the chance of winning an Apple iPod:
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: