[Snort-users] Strange UDP Packets

Ben Vaughn bvaughn at ...5085...
Tue Feb 26 06:26:08 EST 2002


Jason,

	Find out which host on your internal network is emanating the
these packets and use a netstat,lsof,sockstat,ps aux equivalent to find
out the tools that are running on the host.  If you put enough effort in
it you should be able to discover which application on the host is
sending out these packets.

-biv

-----Original Message-----
From: Jason Robertson [mailto:jason at ...3161...] 
Sent: Monday, February 25, 2002 10:22 PM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Strange UDP Packets



I have been noticing at regular intervals UDP packets internal.net 47474
-> 255.255.255.255 47474

I have noticed this was asked on the FW-1 mailling list like 2 years 
ago but there is nothing else on this

Jason



--
Jason Robertson                
Now at the Nation Research Council.



_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3788 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020226/5294f6e2/attachment.bin>


More information about the Snort-users mailing list