[Snort-users] Odd source port

Kendall Lister krl at ...1908...
Thu Apr 26 09:27:35 EDT 2001


Hello,

This does not relate directly to snort, but I hope that someone recognises
it anyway...

My firewall (xxx.xxx.xxx.xxx) was hit by this packet yesterday morning:

input ACCEPT eth1 PROTO=6 63.230.69.10:13117 xxx.xxx.xxx.xxx:21 L=60
S=0x00 I=48855 F=0x4000 T=36 SYN (#39)

13117 is suspiciously similar to 31337 - I'm curious to know if this is
part of a known modus operandi?

Thanks,

Kendall
krl at ...1907...





More information about the Snort-users mailing list