[Snort-users] RE: Bad Loop Back Traffic

Scott Elgram SElgram at ...10477...
Wed Feb 25 06:34:08 EST 2004


Nope,
    There are no F5 products in my network at all.  I took a closer look at
the alerts in acid and source is the interface that the sensor is on and
destination is any number of IP's that SNORT is monitoring.
-Scott Elgram

----- Original Message ----- 
From: "Finney Charles E" <FinneyCharlesE at ...2134...>
To: <snort-users at lists.sourceforge.net>
Sent: Tuesday, February 24, 2004 10:39 AM
Subject: [Snort-users] RE: Bad Loop Back Traffic


>Reply-To: "Scott Elgram" <SElgram at ...10477...>
>From: "Scott Elgram" <SElgram at ...10477...>
>To: <snort-users at lists.sourceforge.net>
>Date: Mon, 23 Feb 2004 13:56:25 -0800
>Organization: VerifPoint/CreDENTALs
>Subject: [Snort-users] Bad Loop Back Traffic
>
>Hello,
>    I have an abundance of alerts telling me
>url[snort] BAD-TRAFFIC loopback traffic on 127.0.0.1:80
>According to snort this is due to improperly configured interfaces.  =
>Which part is improperly configured and how can I fix this? Or have I =
>been hacked?
>
>-Scott Elgram
>IT/Systems Support
>VerifPoint/CreDENTALs
>(949)770-5290 ext. 26

We have seen this traffic in copious quantities from F5 Networks BigIP
systems.  Perchance?

cf



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id56&alloc_id438&op=ick
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=ort-users






More information about the Snort-users mailing list