Re: [Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103

This is a discussion on Re: [Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103 within the Snort forums, part of the System Security and Security Related category; > rule. I know the protocol in question is a routing-related protocol, but > does anyone have any views ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-17-2007
doug schmidt
 
Posts: n/a
Default Re: [Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103

> rule. I know the protocol in question is a routing-related protocol, but
> does anyone have any views or explanation on the normal use of this protocol
> ?


An example of such would be cisco routers configured for HSRP. Routers
will use multicast to send hello's and talk with members of the group.

~doug

On 5/17/07, David Ryan <David.Ryan@quintiles.com> wrote:
>
> Hi all,
>
> I am seeing loads (like 90% of all events) of these events showing up on one
> of my Snort sensors. I have looked at the description here -
> http://www.snort.org/pub-bin/sigs.cgi?sid=2189 - and I
> looked at the rule definition and it appears to match simply on the
> existence of IP protocol 103 as distinct from any payload within it.
>
> I see the traffic coming from two known Cisco routers on the subnet I'm
> monitoring and the traffic is destined for 224.0.0.13 which is the multicast
> address for PIM -
> http://www.networksorcery.com/enp/protocol/pim.htm I have
> also I have seen it on other sites and subnets on the network I am
> monitoring, so I guess whatever function is causing this traffic to
> originate from the router is used across the organisation.
>
> In order to make the output from snort a little more readable (and because
> it is matching on the protocol and not the payload) I have disabled this
> rule. I know the protocol in question is a routing-related protocol, but
> does anyone have any views or explanation on the normal use of this protocol
> ?
>
> Thanks,
>
> David
> ===========================================
> David Ryan
> IT Security Engineer, Global IT Security
> Quintiles, Global IT - Infrastructure, QDUB
>
> david.ryan@quintiles.com
> v: +353-1-819-5186, GMT+0
> m: +353-87-124-9108
> ===========================================
>
>
> ********************** IMPORTANT--PLEASE READ ************************

This
> electronic message, including its attachments, is COMPANY CONFIDENTIAL

and
> may contain PROPRIETARY or LEGALLY PRIVILEGED information. If you are

not
> the intended recipient, you are hereby notified that any use,
> disclosure,

copying, or distribution of this message or any of the
> information included

in it is unauthorized and strictly prohibited. If you
> have received this

message in error, please immediately notify the sender by
> reply e-mail and

permanently delete this message and its attachments, along
> with any copies

thereof. If this electronic message contains a zipped
> attachment and you do

not have a decompression tool, you may download unZIP
> (free of cost)
> from:

http://www.mk-net-work.com/us/uz/unzip.htm.
> Alternatively, you may request

that the attachment be resent in an
> uncompressed format. Thank you.
>

************************************************** **********************

>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by DB2 Express
> Download DB2 Express C - the FREE version of DB2 express and take
> control of your XML. No limits. Just data. Click to get it now.
> http://sourceforge.net/powerbar/db2/
> _______________________________________________
> Snort-users mailing list
> Snort-users@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/...fo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.p...st=snort-users
>


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:13 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0