Firewall Wizards mailing list archives

Re: UDP: port 31790 -> 31789


From: Shane Macaulay <macaulay () itsec net>
Date: Wed, 17 Nov 1999 18:31:59 -0800

Looks like an rpc scan where somebody is trying to bypass
the portmapper (111) and contact cretin rpc services directly.

Shane Macaulay
Ambient Security

Jan Stifter wrote:

hello all,
our firewall logs a lot of packets, coming in from port 31790 to port 31789,
udp protocol. it seems to be a quite usual scan attack. has anybody
encountered anything equal or can anybody explain to me, what kind of
software the possible attacker is expecting at port 31789?

any hints are greatly appreciated

jan stifter
medres ag



Current thread: