[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [SLUG] Weird packets in tcpdump/ngrep



On Wed, Jun 13, 2001 at 05:14:46PM +1000, Jobst Schmalenbach wrote:
> All,
> 
> this is what I see (quite regular actually):
> 
> tcpdump:
> 
> 17:12:39.282431 > piquet.barrett.com.au.40612 > acc8.mel.connect.com.au.33435: udp 10 [ttl 1]
> 17:12:39.412449 < acc8.mel.connect.com.au > piquet.barrett.com.au: icmp: acc8.mel.connect.com.au udp port 33435 unreachable [tos 0xc0]

Off the top of my head, that looks like the product of a traceroute
command.  Note the very low ttl value, and the high port.

-Andrew.

-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug