Increased port activity question
"Walzer, Jeff" <[email protected]> Thu, 11 Aug 2005 10:02:53 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
I am using the Mars appliance from Cisco (formerly Protego) for log consolidation and one thing I've noticed as of late is that an alert is generated with the Cisco 565 cache engine as the source using port 0 going to a destination IP/port of 0.0.0.0/80. I am trying to determine is this is a false positive and standard behavior of the cache engine. Has anyone ever comes across this before? Thanks The information contained in this message and any attachments (collectively, the "Transmission") from Dick's Sporting Goods, Inc. contains confidential information and is intended solely for the named recipient(s). If you are not a named recipient, you are prohibited from copying, distributing or using this Transmission. Please contact the sender immediately by returning the e-mail and deleting the original Transmission. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions