Security Incidents mailing list archives
TCP low port scan
From: jose () BIOCSERVER BIOC CWRU EDU (Jose Nazario)
Date: Mon, 15 May 2000 16:49:27 -0400
Hi all, It's been awfully quiet lately in our corner of the world, but I did catch a low TCP port scan from this morning coming from an MCI WorldCom customer: Name: chi-qbu-nvn-vty5.as.wcom.net Address: 216.192.169.5 The syslog entries that triggered my interest are: May 15 00:53:39 server kernel: TCP connection accepted: ip=216.192.169.5 port=7 uid=0 process=xinetd[27356] May 15 00:53:40 server kernel: TCP connection accepted: ip=216.192.169.5 port=9 uid=0 process=xinetd[27356] May 15 00:53:40 server kernel: TCP connection rejected from 216.192.169.5, port 8 May 15 00:53:40 server kernel: TCP connection rejected from 216.192.169.5, port 10 May 15 00:53:40 server kernel: TCP connection accepted: ip=216.192.169.5 port=13 uid=0 process=xinetd[27356] A nice, nearly sequential scan of the low TCP ports, probably fingerprinting OS's on the basis of open ports and responses. I can't think of much else useful in this range. Oddly, I was unable to find any traces of the host on other services (ie SMTP) or other systems on the subnet. Interesting, haven't seen this sort of thing in a while, I usually see full blown port scans. jose nazario jose () biochemistry cwru edu PGP fingerprint: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80 Public key available at http://biocserver.cwru.edu/~jose/pgp-key.asc
Current thread:
- IP Black list?, (continued)
- IP Black list? Stuart Staniford (May 11)
- Re: IP Black list? Travis Pugh (May 15)
- Re: IP Black list? Jose Nazario (May 15)
- Re: IP Black list? Paul L Schmehl (May 15)
- Re: IP Black list? Travis Pugh (May 16)
- Re: IP Black list? Sebastien Berube (May 15)
- Odd scans of tcp port 12345 Russell Fulton (May 15)
- Re: Odd scans of tcp port 12345 Shadow Boxer (May 16)
- IP Black list? Stuart Staniford (May 11)
- New or Variant Port 109 Scans Stephen P. Berry (May 15)
- Re: IP Black list? Patrick van Zweden (May 15)
- TCP low port scan Jose Nazario (May 15)
- Re: IP Black list? Joe McAlerney (May 15)
- Re: IP Black list? Omachonu Ogali (May 15)
- Re: IP Black list? Emre (May 15)
- Re: IP Black list? Ex Machina (May 15)
- Re: IP Black list? Keith Owens (May 16)