Snort mailing list archives

Help with snort message


From: Ben Beeson <bwbees0 () charter net>
Date: Sun, 29 Feb 2004 23:30:11 -0800

Aloha list,

        I was looking through my logs today and I noticed a few messages like: 

Feb 29 20:18:15 router snort: [1:528:3] BAD TRAFFIC loopback traffic
[Classification: Potentially Bad Traffic] [Priority: 2]: {TCP}
127.0.0.1:80 -> my.router.outer.ip:1815

I have seen a few of these entries rather sporadically in my logs, but
not all seem to use the same port on "my.router.outer.ip"

My question is what would cause something like this?  This message is
from my router box which does not have a web server or anything like it
running.  Basically, this router box runs RH7.2 with secure shell and a
firewall so I am wondering why anything would be looking at the
localhost port 80.   

        Any help anyone could offer that might enlighten me as to where or
whether I need to look would be greatly appreciated.  

Thanks in advance,

Ben 



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: