[Snort-users] [OpenBSD 3.4 + snort 2.0.0b72] Strange Bad Traffic alert generating from 127.0.0.1:80 to the firewall's external ip

Calyth calyth at ...9344...
Sat May 1 01:32:00 EDT 2004


The platform is OpenBSD 3.4 running snort 2.0.0 build 72.
I got this strange alert from snort that repeats itself. It complains of
Bad Traffic loopback traffic (potential) with priority 2, and it's
always from 127.0.0.1:80 to some port on the external IP that greater
than 1024.
Has anyone seen this? I'm running snort with -D -i ep0 -c {path to
snort.conf}

Benton Lam







More information about the Snort-users mailing list