[Snort-users] RE: Bad Loop Back Traffic

Finney Charles E FinneyCharlesE at ...2134...
Tue Feb 24 10:49:01 EST 2004


>Reply-To: "Scott Elgram" <SElgram at ...10477...>
>From: "Scott Elgram" <SElgram at ...10477...>
>To: <snort-users at lists.sourceforge.net>
>Date: Mon, 23 Feb 2004 13:56:25 -0800
>Organization: VerifPoint/CreDENTALs
>Subject: [Snort-users] Bad Loop Back Traffic
>
>Hello,
>    I have an abundance of alerts telling me
>url[snort] BAD-TRAFFIC loopback traffic on 127.0.0.1:80
>According to snort this is due to improperly configured interfaces.  =
>Which part is improperly configured and how can I fix this? Or have I =
>been hacked?
>
>-Scott Elgram
>IT/Systems Support
>VerifPoint/CreDENTALs
>(949)770-5290 ext. 26

We have seen this traffic in copious quantities from F5 Networks BigIP systems.  Perchance?

cf





More information about the Snort-users mailing list