norton AV host discovery scan

From: Ian Melven (imelvenat_private)
Date: Thu Dec 06 2001 - 08:45:53 PST

  • Next message: Michael Garafola: "RE: Gone Worm"

    hi everyone
    
    i was wondering if anyone else has been seeing scans of
    38293/udp recently ?
    
    they seem to be coming from the same source.. and repeat
    1-3 times per day.
    
    snort.org's ports db tells me this is Norton AV host discovery ?
    
    i dug around briefly but couldn't find any published holes in this.
    
    i suspect someone may be misconfigured.
    
    thanks
    ian
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Dec 06 2001 - 11:20:06 PST