Snort mailing list archives
Re: Bad Loop Back Traffic
From: Mat Harris <mat.harris () genestate com>
Date: Tue, 24 Feb 2004 17:36:48 +0000
first, I am no network engineer, I just get paid for it :) I know there are flaws/gaps in my learning. i have seen the same traffic from two linux boxes at one site. they generate about 2 alerts each per hour. by this i mean that they detect the packets. as to who is generating them, there are some windows xp pro clients and a windows 2000 server running as domain controller. I am not very worried about this traffic, I put it down to the fact that both machines are running apache and may be doing some requests across the local interface. On Tue, Feb 24, 2004 at 12:01:56 -0500, bclark () bwkip com wrote:
I have also seen this type of traffic about 200,000 alerts last night. I am not sure but I think it is a clients Windows machine.
-- Cats land on their feet. Toast lands jellyside down. A cat glued to some jelly toast will hover in quantum indecision perl -e'$_=q#: 13_2: 12/o{>: 8_4) (_4: 6/2^-2; 3;-2^\2: 5/7\_/\7: \ 12m m::#;y#:#\n#;s#(\D)(\d+)#$1x$2#ge;print' Yes, of course it's the right cabl [le0: NO CARRIER]
Attachment:
_bin
Description:
Current thread:
- Bad Loop Back Traffic Scott Elgram (Feb 24)
- <Possible follow-ups>
- Re: Bad Loop Back Traffic bclark (Feb 24)
- Re: Bad Loop Back Traffic Mat Harris (Feb 24)
- Re: Bad Loop Back Traffic Frank Knobbe (Feb 24)
- Re: Bad Loop Back Traffic Scott Elgram (Feb 25)
- RE: Bad Loop Back Traffic Finney Charles E (Feb 24)
- Re: RE: Bad Loop Back Traffic Scott Elgram (Feb 25)
- Re: RE: Bad Loop Back Traffic James Nonya (Feb 24)
- Re: Bad Loop Back Traffic SN ORT (Feb 25)
- Re: Bad Loop Back Traffic Scott Elgram (Feb 27)
- Re: Bad Loop Back Traffic Mark . Schutzmann (Feb 27)