[Snort-users] Strange UDP Packets

Mipam mipam at ...266...
Mon Feb 25 19:57:02 EST 2002


> I have been noticing at regular intervals UDP packets
> internal.net 47474 -> 255.255.255.255 47474
> 
> I have noticed this was asked on the FW-1 mailling list like 2 years 
> ago but there is nothing else on this

Hmm i also found nothing on this on iana.
Could be that some ddos clients listening to such a port
Sometimes client who's been hacked have a daemon installed
listening to such a port and somebody is scanning the network to
check whether any machine are listening to abuse them.
Bye,

Mipam.




More information about the Snort-users mailing list