29 Dec
2009
29 Dec
'09
19:41
All, I researching a intrusion and I have netflows that show activity that I can relate back to a rogue install of uTorrent. Many of the netflows show an outside client connecting to the server via the bound service port. (A non-standard one in this case.) But many of the netflows show uTorrent initiating outbound connections from that same port. Is that normal? Does it indicate anything unusual? I'm familiar with FTP have both active and passive opens for the data socket. Is this just the same thing but for torrents? Thanks Greg -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org For additional commands, e-mail: opensuse+help@opensuse.org