[Snort-users] Strange UDP Packets

Jason Robertson jason at ...3161...
Thu Feb 28 10:42:07 EST 2002


I think it might be related to  Novell Netware.  As I am seeing 
information about clients in these packets.

Jason

On 26 Feb 2002 at 4:55, Mipam wrote:

Date sent:      	Tue, 26 Feb 2002 04:55:53 +0100
From:           	Mipam <mipam at ...266...>
To:             	Jason Robertson <jason at ...3161...>
Copies to:      	snort-users at lists.sourceforge.net
Subject:        	Re: [Snort-users] Strange UDP Packets
Send reply to:  	mipam at ...266...

> > I have been noticing at regular intervals UDP packets
> > internal.net 47474 -> 255.255.255.255 47474
> > 
> > I have noticed this was asked on the FW-1 mailling list like 2 years 
> > ago but there is nothing else on this
> 
> Hmm i also found nothing on this on iana.
> Could be that some ddos clients listening to such a port
> Sometimes client who's been hacked have a daemon installed
> listening to such a port and somebody is scanning the network to
> check whether any machine are listening to abuse them.
> Bye,
> 
> Mipam.
> 


--
Jason Robertson                
Network/Security Analyst     
jason at ...3161... 
http://www.ifuture.com, http://www.astroadvice.com, 
http://www.astroeast.com
Also if you are looking for an employee, I may be available soon, so 
feel free to 
contact me for my resume.





More information about the Snort-users mailing list