Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: port 27015

Re: port 27015

From: Paul Robertson <proberts_at_patriot.net>
Date: Sat, 3 Jan 2004 17:57:06 -0500 (EST)

On Fri, 2 Jan 2004, hermit921 wrote:

> I am aware of the Half-Life game association. What I saw was 10 different

AFAICT, Half-Life is on UDP 27015- anyone with a server that can check?

> IP sources scanning my entire class B on port 27015, all starting within
> one hour of each other. That didn't sound like a normal game
> behavior. But after that day, the scans didn't return.

Well, there are a few possible explainations:

1. Someone scanning for game servers.
    A) Census type thing.
    B) New sploit to play with.
    C) Bad software.

2. Someone scanning for zombies.

3. Someone fingerprinting the network.

Do you have any packets, or just log entries? Was there any other pattern
to the traffic (source ports, etc?) Were the source addresses related in
any way? Was it one packet per IP, or multiple, and if multiple, same or
different sorce port? Any particular sequence number or flags on?

I generally tend to try to contact one of the source networks if I can
find one that looks like it's relatively responsive- doesn't pay off
often, but when it does, it normally does well.

Thanks,

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
proberts_at_patriot.net which may have no basis whatsoever in fact."
probertson_at_trusecure.com Director of Risk Assessment TruSecure Corporation
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Jan 03 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos