|
Security Incidents
mailing list archives
Re: UDP Probes (?) from port 28432 to 28431 ?
From: Alexander.Schreiber () INFORMATIK TU-CHEMNITZ DE (Alexander Schreiber)
Date: Tue, 7 Mar 2000 15:12:27 +0100
Hi !
On Sat, 4 Mar 2000, Xander Jansen wrote:
Has anyone seen UDP subnet-sweeps to port 28431 ? We've received a few
reports the last months about rather persistent and recurring subnet-scans
targetted at this specific port. All the probes are short UDP packets with
source port 28432 and destination port 28431. Typical pattern is also that
within a few seconds a complete subnet (/24 for example) is probed on this
Yes, a client of mine has two IP which are visible on the outside and they
are regularly receiving these probes (not exactly - the firewall on the border
is logging and dropping those packets). First detected on Jan 4 00:17:35
(MET), 27 attempts today, last Mar 6 19:41:25 (MET). The packets aimed
at the two visible IP's come in within one second.
Sources are Dialups all over the world (including one from the
Arabian Emirates) - as usual.
Regards,
Alex.
--
------------------------------------------------------------------------------
EMail : als () thangorodrim de | WWW : http://www.thangorodrim.de/
If privacy is outlawed, only outlaws will have | Ceterum censeo Parva Mollia
privacy. (Philip Zimmerman, author of PGP) | esse delendam.
By Date
By Thread
Current thread:
|