Snort mailing list archives

Re: Strange UDP Packets


From: "Jason Robertson" <jason () ifuture com>
Date: Thu, 28 Feb 2002 13:40:42 -0500

I think it might be related to  Novell Netware.  As I am seeing 
information about clients in these packets.

Jason

On 26 Feb 2002 at 4:55, Mipam wrote:

Date sent:              Tue, 26 Feb 2002 04:55:53 +0100
From:                   Mipam <mipam () ibb net>
To:                     Jason Robertson <jason () ifuture com>
Copies to:              snort-users () lists sourceforge net
Subject:                Re: [Snort-users] Strange UDP Packets
Send reply to:          mipam () ibb net

I have been noticing at regular intervals UDP packets
internal.net 47474 -> 255.255.255.255 47474

I have noticed this was asked on the FW-1 mailling list like 2 years 
ago but there is nothing else on this

Hmm i also found nothing on this on iana.
Could be that some ddos clients listening to such a port
Sometimes client who's been hacked have a daemon installed
listening to such a port and somebody is scanning the network to
check whether any machine are listening to abuse them.
Bye,

Mipam.



--
Jason Robertson                
Network/Security Analyst     
jason () ifuture com 
http://www.ifuture.com, http://www.astroadvice.com, 
http://www.astroeast.com
Also if you are looking for an employee, I may be available soon, so 
feel free to 
contact me for my resume.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: