[unisog] Port 0

Rudolph Pereira rudolph at usyd.edu.au
Mon Oct 31 22:12:50 GMT 2005


On Mon, Oct 31, 2005 at 05:07:03PM +0100, Florian Weimer wrote:
> * jeff murphy:
> 
> > 2005-10-27 22:49:00    0:00:00 128.205.10.254      0 224.0.0.1
> > 0 IP PROTOCOL 2
> 
> This is IGMP traffic (IP protocol 2) destined towards a multicast
> address.  Looks pretty standard.  (I would disable all multicast stuff
> on interfaces facing untrusted networks, though, just in case.)
So, given that the only solid report of udp/0 traffic is actually IGMP,
I'd still, for one, be interested in any other evidence that udp/0 is
associated with valid traffic.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://www.dshield.org/pipermail/unisog/attachments/20051101/feefa86a/attachment.bin


More information about the unisog mailing list