Security Incidents mailing list archives
Re: Very Strange Attack
From: "Osvaldo J. Filho" <osvaldojaneri () UOL COM BR>
Date: Wed, 7 Feb 2001 14:44:02 -0200
A quick search at Snort.conf Port Database and on my Palm TCP/UDP Ports text didn't returned anything about the Sport or the Dport. I guess that it can be a particular rootkit/worm backdoor port, that the attacker can be looking for. Or maybe, if others machine were hit by the same pkt, he is just using this destination port to map your network (instead of using ping, he tries to connect and listen for the RSTS). Any other ideas, anyone? Cheers, --- Osvaldo J. Filho Unix Security Specialist/Consultant <osvaldojaneri () uol com br> --- On Wed, 7 Feb 2001, Mendoza, Luis wrote:
Hi everybody, I had received this traffic from Internet, in all cases the destinations port are not well-known but are the same (TCP:21536) and the source port idem (TCP:18245) Is this traffic associated to some kind of attack or anything else? Thanks Luis Mendoza Feb 3 15:11:58 66.50.24.49:18245 -> a.b.c.44:21536 VECNA *******U Feb 3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 VECNA 2****P*U RESERVEDBITS Feb 3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 XMAS 2**F*P*U RESERVEDBITS Feb 3 15:12:05 66.50.24.49:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU RESERVEDBITS Feb 3 18:44:15 63.91.226.239:18245 -> a.b.c.44:21536 VECNA *******U Feb 3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 VECNA 2****P*U RESERVEDBITS Feb 3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 XMAS 2**F*P*U RESERVEDBITS Feb 3 18:44:22 63.91.226.239:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU RESERVEDBITS Feb 3 18:44:26 63.91.226.239:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 3 21:37:07 63.91.227.90:18245 -> a.b.c.44:21536 VECNA *******U Feb 3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 VECNA 2****P*U RESERVEDBITS Feb 3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 XMAS 2**F*P*U RESERVEDBITS Feb 3 21:37:14 63.91.227.90:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU RESERVEDBITS Feb 3 21:37:18 63.91.227.90:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 4 22:06:13 66.50.25.19:18245 -> a.b.c.44:21536 VECNA *******U Feb 4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U RESERVEDBITS Feb 4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 VECNA 2****P*U RESERVEDBITS Feb 4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 XMAS 2**F*P*U RESERVEDBITS
Current thread:
- Very Strange Attack Mendoza, Luis (Feb 07)
- Re: Very Strange Attack Osvaldo J. Filho (Feb 07)
- Re: Very Strange Attack Fernando Cardoso (Feb 07)
- Re: Very Strange Attack Osvaldo J. Filho (Feb 07)
- Re: Very Strange Attack Fernando Cardoso (Feb 07)
- <Possible follow-ups>
- Re: Very Strange Attack Benninghoff, John (Feb 07)
- Re: Very Strange Attack Fulton L. Preston Jr. (Feb 07)
- Re: Very Strange Attack Fulton L. Preston Jr. (Feb 09)
- Re: Very Strange Attack Mendoza, Luis (Feb 10)
- Re: Very Strange Attack Osvaldo J. Filho (Feb 07)