[Bro] Scan UDP

Forest Monsen fmonsen at ucsc.edu
Fri Mar 11 14:53:10 PST 2016

On 03/09/2016 04:44 PM, Nicolas Macia CESPI wrote:
> The problem was detected with NTP and DNS servers with a lot of
> activity. The script alerts that this servers were scanning UDP ports
> when in reality they were responding to requests to their services.

Ah yes. We saw this behavior with Bluehost recursive DNS. I don't have a
pcap, I'm sorry.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
Url : http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20160311/44c707af/attachment.bin 

More information about the Bro mailing list