Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




basics logo Security Basics mailing list archives

More port scanning - except source port is changing
From: Richard.Conto () gmail com
Date: Sat, 29 Nov 2008 20:35:14 -0700

What is with TCP port scanning where the source port changes?

I just noticed a situation where what appears to be inverse port scanning is occuring with the source TCP port 
changing.  3 attempts are made, 3 seconds and 6 seconds apart. Then the source port changes.  In the brief time I've 
watched it, the source port always increases. The destination port is 38490.

Is this an attempt by a bot-net controller trying to re-establish control over it's zombies?


  By Date           By Thread  

Current thread:
  • More port scanning - except source port is changing Richard . Conto (Dec 01)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]