Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Curious packets to port 48

Curious packets to port 48

From: aedron <aedron_at_DAEWERK.NET>
Date: Mon, 1 Jan 2001 23:15:27 -0600

Something interesting popped up in the logs this weekend:

Dec 31 05:12:12 xyzzy kernel: Packet log: input DENY eth0 PROTO=TCP
24.91.65.96:1355 xxx.xxx.xxx.xxx:48 L=48:28:0 S=0x00 I=12916:120828959:0
F=0x0040 T=110 .S.... (#26)
Dec 31 05:12:15 xyzzy kernel: Packet log: input DENY eth0 PROTO=TCP
24.91.65.96:1355 xxx.xxx.xxx.xxx:48 L=48:28:0 S=0x00 I=38772:120828959:0
F=0x0040 T=110 .S.... (#26)

Can't recall ever having seen an attempt to connect to 48 on this
machine before. Is there a (new) auditd exploit out there?

Just curious,
Aedron
Received on Jan 02 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos