[Snort-users] rpc.statd

skop d'skop skop at ...2175...
Tue Jun 5 20:51:49 EDT 2001


hi guys,
come across this alert lately for my network

[**] IDS10 - RPC - portmap-request-rstatd [**]

May 30 11:25:15 A.B.C.80:3348 -> X.Y.Z.9:111 SYN ******S*
May 30 11:25:16 A.B.C.80:726 -> X.Y.Z.9:111 UDP
May 20 11:25:15 A.B.C.80:3351 -> X.Y.Z.12:111 SYN ******S*
May 20 11:25:15 A.B.C.80:3352 -> X.Y.Z.13:111 SYN ******S*
May 20 11:25:16 208.131.80.80:727 -> X.Y.Z.13:111 UDP

and i'm wondering what kind of scanning / tool that trigger this alert.

i 've done with #rpcinfo -p hostname and #nmap -sU -sR  hostname , yet no similiar output.





-skop
___________________________________________________________________________
Visit http://www.visto.com/info, your free web-based communications center.
Visto.com. Life on the Dot.





More information about the Snort-users mailing list