Security Incidents mailing list archives

Re: Very Strange Attack


From: "Osvaldo J. Filho" <osvaldojaneri () UOL COM BR>
Date: Wed, 7 Feb 2001 14:44:02 -0200

        A quick search at Snort.conf Port Database and on my Palm TCP/UDP
Ports text didn't returned anything about the Sport or the Dport.

        I guess that it can be a particular rootkit/worm backdoor port,
that the attacker can be looking for. Or maybe, if others machine were
hit by the same pkt, he is just using this destination port to map your
network (instead of using ping, he tries to connect and listen for the
RSTS).

        Any other ideas, anyone?

Cheers,
---
Osvaldo J. Filho
Unix Security Specialist/Consultant
<osvaldojaneri () uol com br>
---

On Wed, 7 Feb 2001, Mendoza, Luis wrote:

Hi everybody,

I had received this traffic from Internet, in all cases the destinations
port are not well-known but are the same (TCP:21536) and the source port
idem (TCP:18245)

Is this traffic associated to some kind of attack or anything else?

Thanks

Luis Mendoza

Feb  3 15:11:58 66.50.24.49:18245 -> a.b.c.44:21536 VECNA *******U
Feb  3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS
Feb  3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 VECNA 2****P*U
RESERVEDBITS
Feb  3 15:12:02 66.50.24.49:18245 -> a.b.c.44:21536 XMAS 2**F*P*U
RESERVEDBITS
Feb  3 15:12:05 66.50.24.49:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU
RESERVEDBITS

Feb  3 18:44:15 63.91.226.239:18245 -> a.b.c.44:21536 VECNA *******U
Feb  3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS
Feb  3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 VECNA 2****P*U
RESERVEDBITS
Feb  3 18:44:19 63.91.226.239:18245 -> a.b.c.44:21536 XMAS 2**F*P*U
RESERVEDBITS
Feb  3 18:44:22 63.91.226.239:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU
RESERVEDBITS
Feb  3 18:44:26 63.91.226.239:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS

Feb  3 21:37:07 63.91.227.90:18245 -> a.b.c.44:21536 VECNA *******U
Feb  3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS
Feb  3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 VECNA 2****P*U
RESERVEDBITS
Feb  3 21:37:11 63.91.227.90:18245 -> a.b.c.44:21536 XMAS 2**F*P*U
RESERVEDBITS
Feb  3 21:37:14 63.91.227.90:18245 -> a.b.c.44:21536 INVALIDACK 2***R*AU
RESERVEDBITS
Feb  3 21:37:18 63.91.227.90:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS

Feb  4 22:06:13 66.50.25.19:18245 -> a.b.c.44:21536 VECNA *******U
Feb  4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 NOACK 2*SFRP*U
RESERVEDBITS
Feb  4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 VECNA 2****P*U
RESERVEDBITS
Feb  4 22:06:16 66.50.25.19:18245 -> a.b.c.44:21536 XMAS 2**F*P*U
RESERVEDBITS



Current thread: