[Snort-users] Odd source port

Kendall Lister krl at ...1908...
Thu Apr 26 09:27:35 EDT 2001


This does not relate directly to snort, but I hope that someone recognises
it anyway...

My firewall (xxx.xxx.xxx.xxx) was hit by this packet yesterday morning:

input ACCEPT eth1 PROTO=6 xxx.xxx.xxx.xxx:21 L=60
S=0x00 I=48855 F=0x4000 T=36 SYN (#39)

13117 is suspiciously similar to 31337 - I'm curious to know if this is
part of a known modus operandi?


krl at ...1907...

More information about the Snort-users mailing list