[Snort-users] ICMP Packets.

Jason Haar Jason.Haar at ...294...
Mon Aug 26 22:02:01 EDT 2002


On Mon, Aug 26, 2002 at 09:37:12PM -0400, larosa, vjay wrote:
> Yeah we were pretty sure that this is some sort of JPEG information
> in the ICMP packet. I have seen some other activity between
> ports 88 and 1107 as well with the hosts involved in the ICMP
> conversations. I did manage to come across another post somewhere
> else talking about this same kind of activity, this was the post.
> 

All I can say is "me too". However, I've seen it between two internal hosts,
so I think it's some spooty ping-type program some app uses - I don't think
it's a tunnel.

I'd like to know what it is too...

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1




More information about the Snort-users mailing list