[Snort-users] Odd source port
krl at ...1908...
Thu Apr 26 09:27:35 EDT 2001
This does not relate directly to snort, but I hope that someone recognises
My firewall (xxx.xxx.xxx.xxx) was hit by this packet yesterday morning:
input ACCEPT eth1 PROTO=6 220.127.116.11:13117 xxx.xxx.xxx.xxx:21 L=60
S=0x00 I=48855 F=0x4000 T=36 SYN (#39)
13117 is suspiciously similar to 31337 - I'm curious to know if this is
part of a known modus operandi?
krl at ...1907...
More information about the Snort-users