Security Basics mailing list archives

More port scanning - except source port is changing


From: Richard.Conto () gmail com
Date: Sat, 29 Nov 2008 20:35:14 -0700

What is with TCP port scanning where the source port changes?

I just noticed a situation where what appears to be inverse port scanning is occuring with the source TCP port 
changing.  3 attempts are made, 3 seconds and 6 seconds apart. Then the source port changes.  In the brief time I've 
watched it, the source port always increases. The destination port is 38490.

Is this an attempt by a bot-net controller trying to re-establish control over it's zombies?


Current thread: