[Snort-users] udp/4156

Andreas Östling andreaso at ...236...
Tue Sep 24 08:40:09 EDT 2002


On Tuesday 24 September 2002 16.33, Colin Wu wrote:
> Hi Snorters,
>
> Has anyone seen, or know what traffic might be using udp/4156 as both
> source and destination? I had a look on the Internet Ports Database but
> found no reference to it. A host on my network seems to be receiving a
> lot of these from all over the planet. Not enough bandwidth usage to be
> noticable but snort picked up "bad frag bits" on some of the packets.

New Slapper variant.

http://isc.incidents.org/aion.html

/Andreas





More information about the Snort-users mailing list