Security Basics mailing list archives

Slow scan on high-ports?


From: Rolf Jürrens <security () rolf-juerrens de>
Date: Tue, 29 Oct 2002 09:39:19 +0100

Hi everyone,

in our firewall-logs I see a slow scan  over our whole network  from one IP address on tcp ports >65300. The scan lasts 
now about 24 hours with only 50 packets. What is the purpose of such a scan? Since all ports are normally closed in 
these ranges, no one can expect to gather information about a network - am I right? Or are there any interesting ports 
in this range? By the way: the IP address appears in the dshield.org database as an attacker address.

Greetings

Rolf


______________________________________________________________________________
Die drei G des Glücks: Gemeinsam garantiert gewinnen! 
Jetzt mittippen! https://spielgemeinschaften.web.de/?mc=021101


Current thread: