Intrusion Detection Systems mailing list archives

RE: Scanning on tcp port 27374


From: arsen () gnac com (Thomas J. Arseneault)
Date: Thu, 27 Apr 2000 10:41:10 -0700


Archive: http://msgs.securepoint.com/ids
FAQ: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au
Fromhttp://www.robertgraham.com/pubs/firewall-seen.html

27374           Sub-7           Trojan Horse (TCP). See the section on SubSeven for more
details.

-----Original Message-----
From: owner-ids () uow edu au [mailto:owner-ids () uow edu au]On Behalf Of
Benninghoff, John
Sent: Wednesday, April 26, 2000 12:47 PM
To: ids () uow edu au
Subject: IDS: Scanning on tcp port 27374


Archive: http://msgs.securepoint.com/ids
FAQ: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
HELP: Having problems... email questions to ids-owner () uow edu au
NOTE: Remove this section from reply msgs otherwise the msg will bounce.
SPAM: DO NOT send unsolicted mail to this list.
UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au
------------------------------------------------------------------
-----------
Hello all,

I've been lurking on IDS for several months now and I have a question for
the list...

I am currently working with Network ID using SHADOW, and I have
seen several
sequential and semi-sequential scans on tcp port 27374. I have
not been able
to figure out what exploit or service these scans are looking
for, and I was
wondering if anyone knew what service runs on this port, or is it
simply an
arbitrary port used by a scanning tool ? Also, has anyone else come across
these types of scans ?

Any info would be appreciated. Thanks.

-------------------------------------
John A Benninghoff
mailto:jabenninghoff () dainrauscher com



Current thread: