[Bro] Scan UDP
fmonsen at ucsc.edu
Fri Mar 11 14:53:10 PST 2016
On 03/09/2016 04:44 PM, Nicolas Macia CESPI wrote:
> The problem was detected with NTP and DNS servers with a lot of
> activity. The script alerts that this servers were scanning UDP ports
> when in reality they were responding to requests to their services.
Ah yes. We saw this behavior with Bluehost recursive DNS. I don't have a
pcap, I'm sorry.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 836 bytes
Desc: OpenPGP digital signature
Url : http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20160311/44c707af/attachment.bin
More information about the Bro