Security Incidents mailing list archives
Re: Odd UPD scan
From: grzesjan () ONET PL (Grzegorz Janoszka)
Date: Fri, 17 Mar 2000 09:26:33 +0100
On Wed, 15 Mar 2000, David Meissner wrote:
For several weeks now I've noticed scans of UDP port 137, but the odd thing is that the source address is spoofed as a private IP address. I don't
IMHO it's not a scan. Some misconfigured networks without full masquarading may send such packets.
Can anyone suggest what might be going on?
Use some filters on packets comming into Your network and discard packets originating from private addresses. -- Grzegorz Janoszka, Optimus Pascal SA (ONET.PL) NA
Current thread:
- Odd UPD scan David Meissner (Mar 15)
- Re: Odd UPD scan Bill Pennington (Mar 16)
- Re: Odd UPD scan Graeme Fowler (Mar 20)
- Re: Odd UPD scan Grzegorz Janoszka (Mar 17)
- <Possible follow-ups>
- Re: Odd UPD scan Randy Mclean (Mar 17)
- Re: Odd UPD scan Rainer Weikusat (Mar 17)
- Re: Odd UPD scan Bill Pennington (Mar 20)
- Re: Odd UPD scan Pavel Kankovsky (Mar 21)
- NetBIOS info Robert Graham (Mar 21)
- Re: NetBIOS info Bill Pennington (Mar 22)
- Strange probe Stuart Staniford-Chen (Mar 24)
- Re: NetBIOS info Robert Graham (Mar 27)
- Syn scans to 4045 Joey McAlerney (Mar 27)
- Re: Odd UPD scan Bill Pennington (Mar 16)