Hi there, In the past few days, my IDS has been picking up traffic coming from port 20480 (on Internet servers) to port 6667 (internal desktops). Both ports are commonly used by trojan horse programs. Has anyone else seens this?
10/10-11:50:01.977897 204.x.x.x:20480 -> 192.168.0.199:6667 TCP TTL:255 TOS:0x10 ID:0 IpLen:20 DgmLen:195 Thanks, Kip Sr. __________________________________________________ Do you Yahoo!? Faith Hill - Exclusive Performances, Videos & More http://faith.yahoo.com