|
Security Incidents
mailing list archives
UDP Probes (?) from port 28432 to 28431 ?
From: Xander.Jansen () SURFNET NL (Xander Jansen)
Date: Sat, 4 Mar 2000 11:45:28 +0100
Hi,
Has anyone seen UDP subnet-sweeps to port 28431 ? We've received a few
reports the last months about rather persistent and recurring subnet-scans
targetted at this specific port. All the probes are short UDP packets with
source port 28432 and destination port 28431. Typical pattern is also that
within a few seconds a complete subnet (/24 for example) is probed on this
port (and this port only). (I'm sorry to say that we don't have any info
on the contents of these packets yet).
I was wondering if anyone knows about either a valid or malicious
application using these ports (I couldn't find any reference in the usual
portlists) ?
Thanks,
Xander Jansen
CERT-NL/SURFnet
By Date
By Thread
Current thread:
|