TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------
Hello everyone,
For the past week, I have been receiving strange
alerts from my RealSecure 6.5 network sensor :
The 'Trace_Route' event is being triggered several
times a day, with the source address being that of my
company's class C network (x.y.z.0), and the
destination address being an external IP address,
which remains identical in all the alerts. I have no
alerts with this external IP as source.
Has anyone encountered this type of alert ? Could this
be a side effect of inbound traffic coming from the
external address ? Or should I search the origin
inside my network (eventual trojan horse attempting to
call home, or something like that) ?
Thanks
Chris
'Trace_Route' event detected by the RealSecure
'network_sensor_1' at 'x.x.x.x'.
Details:
Source Address: <my class C network>
Source MAC Address: xx:xx:xx:xx:xx:xx
Destination Address: <ip address outside>
Destination MAC Address: xx:xx:xx:xx:xx:xx
Time: 2002-08-27 13:46:59 UTC
Protocol: ICMP (1)
ICMP Type: Echo Request
ICMP Code: None
Priority: low
Actions:
DISPLAY=Default:0,LOGDB=LogWithoutRaw:0,EMAIL=Default:0
Event Specific Information:
__________________________________________________
Do You Yahoo!?
Yahoo! Finance - Get real-time stock quotes
http://finance.yahoo.com