[Snort-users] same source and destination
podrimja at ...9360...
Thu Dec 4 05:42:01 EST 2003
In recent days I'm seeing some alerts from my snort sensor about bad-traffic (same src/dst), the IP is 184.108.40.206 and the traffic is tcp with source port 80. I identified the user and I talked with him to stop it but he says that he doesn't know if someone from his company is sending this kind of traffic. So, does anyone know if this kind of traffic is generated from some kind of virus or someone is sending spoofed traffic as I'm thinking.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users