Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Large number of packets on TCP/12159

Large number of packets on TCP/12159

From: David Vernon <firewall-wizards_at_ladadee.com>
Date: Sat, 13 Sep 2003 11:51:32 -0700

In the last few days my dialup router has dropped a large number of
packets on TCP port 12159 and I can not find any info on that port. The
dialup is running IPTables filters and drops all inbound on ppp0. Last
night the packets came from 30+ unique IPs with 80 to several hundred
packets each and totaled about ~5 MBs worth of SYN packets (no small
effort time wise for them over a 42kb dial-up line).

I did a tcpdump on that port for a couple of packets. It is @
http://ladadee.com/dump/port12159.cap.tar

Any idea what this is?

Thanks,
David Vernon

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Sep 14 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos