Security Incidents mailing list archives
Re: Port 33434 and decoy-scanning
From: ryan () SECURITYFOCUS COM (Ryan Russell)
Date: Thu, 9 Mar 2000 13:45:51 -0800
Don't know the what or why but have been seeing the same traffic for about week, same source addresses. The source ports are the same each pass, and occurs about the same time each day for a period of an hour or so. The pattern is traceroute like, generally 3 packets with TTL=1 followed by 1 to 3 packets with TTL=2. --
That's traceroute. Ryan
Current thread:
- Re: web related oddity Oliver Friedrichs (Feb 29)
- <Possible follow-ups>
- Re: web related oddity Richard Bejtlich (Mar 04)
- Port 33434 and decoy-scanning Jan Roger Wilkens (Mar 08)
- Re: Port 33434 and decoy-scanning Pete Clements (Mar 08)
- Re: Port 33434 and decoy-scanning Ryan Russell (Mar 09)
- Port 33434 and decoy-scanning Jan Roger Wilkens (Mar 08)
- Re: web related oddity Ryan Russell (Mar 08)
- Re: web related oddity Christopher L. Morrow (Mar 08)
- Re: web related oddity Donald McLachlan (Mar 07)
- Re: web related oddity Matthew S. Hallacy (Mar 08)
- Re: web related oddity Bill Pennington (Mar 08)
- ftp scan (was Re: web related oddity) Matthew S. Hallacy (Mar 08)
- Re: web related oddity Matthew S. Hallacy (Mar 08)