<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: fun with tcpdump bpf and udp</title>
	<atom:link href="http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp/feed" rel="self" type="application/rss+xml" />
	<link>http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp</link>
	<description>it's better then a sharp stick in the eye!</description>
	<lastBuildDate>Fri, 29 Jan 2010 00:14:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Axthrower</title>
		<link>http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp/comment-page-1#comment-155</link>
		<dc:creator>Axthrower</dc:creator>
		<pubDate>Tue, 12 Feb 2008 13:06:34 +0000</pubDate>
		<guid isPermaLink="false">http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp#comment-155</guid>
		<description>Your tcpdump skills are fearsome!</description>
		<content:encoded><![CDATA[<p>Your tcpdump skills are fearsome!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Martin</title>
		<link>http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp/comment-page-1#comment-153</link>
		<dc:creator>Greg Martin</dc:creator>
		<pubDate>Mon, 11 Feb 2008 16:38:06 +0000</pubDate>
		<guid isPermaLink="false">http://trepullins.net/02-09-2008/fun-with-tcpdump-bpf-and-udp#comment-153</guid>
		<description>great tip!  Just thought it was bizarre to see udp traffic destined for port 80!  Sounds like botnet backdoor channelish...

Never in my experience have I seen a process listen on udp port 80.  It is extremely common for attackers to try an evade secadmin by sourcing their udp or tcp scans from port 80 to try and sneak in at web traffic, maybe you saw backscatter from a portscan generated from the inside?

-G</description>
		<content:encoded><![CDATA[<p>great tip!  Just thought it was bizarre to see udp traffic destined for port 80!  Sounds like botnet backdoor channelish&#8230;</p>
<p>Never in my experience have I seen a process listen on udp port 80.  It is extremely common for attackers to try an evade secadmin by sourcing their udp or tcp scans from port 80 to try and sneak in at web traffic, maybe you saw backscatter from a portscan generated from the inside?</p>
<p>-G</p>
]]></content:encoded>
	</item>
</channel>
</rss>

