[Snort-users] Strange traffic?

Vjay LaRosa vjayl at ...3331...
Wed Sep 26 07:58:03 EDT 2001


Hello,

Can some one help me here. I can't think of any reason that I would be
seeing this traffic.

09/26-09:10:17.709508  [**] [1:0:0] TFTP Traffic [**] [Classification:
Potentially Bad Traffic] [Priority: 2] {UDP} X.X.X.X:53 -> X.X.X.X:69

Why would there be a TFTP session using the source port for DNS? Any
ideas would be appreciated. Thanks!

vjl

--
 V.Jay LaRosa                           EMC Corporation
 Systems Administrator                  171 South Street
 (508)435-1000 ext 14957                Hopkinton, MA 01748
 (508)497-8082 fax                      www.emc.com


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20010926/f79c823d/attachment.html>


More information about the Snort-users mailing list