[Snort-users] snort alert

Joerg Weber j.weber at ...8292...
Tue Sep 16 01:02:10 EDT 2003


Hi,

> Hello!!!
> In snort alert I see this lines :
> 
> [**] SCAN UPNP service discover attempt [**]
> 09/15-16:39:10.579722 172.19.1.79:1198 -> 239.255.255.250:1900
> UDP TTL:4 TOS:0x0 ID:16768 IpLen:20 DgmLen:161
> Len: 133
> 
> What they mean and where I can read about it?
> Thank for any help.
> 
I'm sure you just forgot to look into the archives, so here's a link:

http://marc.theaimsgroup.com/?l=snort-users&w=2&r=1&s=scan+upnp&q=b

Cheers,

Joerg

-- 
Joerg Weber
Network Security

infoServe GmbH
Nell-Breuning-Allee 6
D-66115 Saarbruecken

T: (0681) 8 80 08 - 0
F: (0681) 8 80 08 - 33
www.infos.de
E: j.weber at ...8292...
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20030916/343ce930/attachment.sig>


More information about the Snort-users mailing list