TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Hello everyone,

For the past week, I have been receiving strange
alerts from my RealSecure 6.5 network sensor :
The 'Trace_Route' event is being triggered several
times a day, with the source address being that of my
company's class C network (x.y.z.0), and the
destination address being an external IP address,
which remains identical in all the alerts. I have no
alerts with this external IP as source.

Has anyone encountered this type of alert ? Could this
be a side effect of inbound traffic coming from the
external address ? Or should I search the origin
inside my network (eventual trojan horse attempting to
call home, or something like that) ?

Thanks
Chris


'Trace_Route' event detected by the RealSecure
'network_sensor_1' at 'x.x.x.x'.
Details:
        Source Address: <my class C network>
        Source MAC Address: xx:xx:xx:xx:xx:xx
        Destination Address: <ip address outside>
        Destination MAC Address: xx:xx:xx:xx:xx:xx
        Time: 2002-08-27 13:46:59 UTC
        Protocol: ICMP (1)
        ICMP Type: Echo Request
        ICMP Code: None
        Priority: low
        Actions:
DISPLAY=Default:0,LOGDB=LogWithoutRaw:0,EMAIL=Default:0
        Event Specific Information:

__________________________________________________
Do You Yahoo!?
Yahoo! Finance - Get real-time stock quotes
http://finance.yahoo.com


Reply via email to