Security Incidents mailing list archives

tcp port 8000 from ss06.live365.com


From: robertj () WIREHUB NL (Robert Joosten)
Date: Tue, 23 May 2000 21:11:45 +0200


Hi,

My firewall blocked quite a few connection attempts to port 8000 (I've seen
iRDMI listed; still don't know what that is ;(.

One log example:
"23/05/2000 20:41:10.029738 tun0 @0:13 b ss06.live365.com,45514 ->
ipxxx-xx-xxx-xxx.xxx.wirehub.net,8000 PR tcp len 20 44 -S IN"

The block did occure at: 20:41:06, 20:41:10, 20:41:16, 20:41:29, 20:41:58
and 20:42:51.

I've never seen such a attempt before. www.live365.com seemed to be home of
a broadcast station. my syslog maps IP > addres and I don't have captured
data-packet to look at right now.

Anyone has seen simular attempts logged or tell me what that port is used for ?

r,
-= Robert


Current thread: