Full Disclosure mailing list archives
Re: TCP Port 42 port scans? What the heck over...
From: "Maxime Ducharme" <mducharme () cybergeneration com>
Date: Tue, 14 Dec 2004 10:21:03 -0500
Hi James,
I see the same thing here, this IP scanned 3 of our networks
(see attached log file).
TCP ID is always 57370
Source port : 6000
Dest port : 42
Nothing is running on tcp port 42 here.
I'd be interested in knowing what it is too, I'll open
a netcat listener at my home and let you know if I catch
anything.
I also sent a notice to 131.252.0.0/16 tech handle in
ARIN's database, and they replied me 4h later.
Seems many other networks were hit byt this IP :
http://www.mynetwatchman.com/LID.asp?IID=140488860
Have a nice day
Maxime Ducharme
Programmeur / Spécialiste en sécurité réseau
----- Original Message -----
From: "James Lay" <jlay () ameriben com>
To: "Full-Disclosure (E-mail)" <full-disclosure () lists netsys com>
Sent: Monday, December 13, 2004 8:46 AM
Subject: [Full-disclosure] TCP Port 42 port scans? What the heck over...
Here they be. ODD. Anyone else seeing this? Dec 13 06:41:49 gateway kernel: Web netrecall drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.19.1 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Web1 drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.18.1 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Web netrecall drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.19.4 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 workbox kernel: IN=eth0 OUT= MAC=00:60:97:a5:76:36:00:10:7b:90:bc:30:08:00 SRC=131.252.116.141 DST=10.1.200.10 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Web netrecall drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.19.7 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: X12 drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.20.14 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Web netrecall drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.19.2 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Htpedi drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.20.17 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 Dec 13 06:41:49 gateway kernel: Edirecall drops:IN=br0 OUT=br0 PHYSIN=eth1 PHYSOUT=eth0 SRC=131.252.116.141 DST=10.1.20.12 LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=57370 DF PROTO=TCP SPT=6000 DPT=42 WINDOW=65535 RES=0x00 SYN URGP=0 James Lay Network Manager/Security Officer AmeriBen Solutions/IEC Group Deo Gloria!!! _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Attachment:
tcp42.log
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: TCP Port 42 port scans? What the heck over..., (continued)
- Re: TCP Port 42 port scans? What the heck over... Kevin Finisterre (Dec 15)
- Re: TCP Port 42 port scans? What the heck over... wastedimage (Dec 16)
- Re: TCP Port 42 port scans? What the heck over... Valdis . Kletnieks (Dec 22)
- Message not available
- Fwd: TCP Port 42 port scans? What the heck over... wastedimage (Dec 23)
- Security breach database n30 (Dec 16)
- Re: Security breach database Martin Mkrtchian (Dec 20)
- Re: Security breach database Valdis . Kletnieks (Dec 21)
- Re: Security breach database Willem Koenings (Dec 23)
- Re: Security breach database Barrie Dempster (Dec 23)
- Re: Security breach database Paul Laudanski (Dec 24)
- Re: TCP Port 42 port scans? What the heck over... Maxime Ducharme (Dec 22)
- Re: TCP Port 42 port scans? Scot Bryhan (Dec 23)
