Security Incidents mailing list archives

Anyone seen this UDP source port 7001 traffic?


From: Faron.Golden () Gunter AF mil
Date: Thu, 17 Apr 2003 16:53:07 -0500

Anyone seen or have an idea what these packets may be?  The source is a
Microsoft host with lots of records at Incidents.  From tcpdump man the
packets appear to be RPC related...

2003/04/17-00:05:53.007245 65.54.240.61.7001 > 192.168.189.72.57208: [|rx]
(20) 
2003/04/17-00:06:47.882910 65.54.240.61.7001 > 192.168.189.72.57192: [|rx]
(20) 
2003/04/17-00:09:43.120563 65.54.240.61.7001 > 192.168.174.69.65301: [|rx]
(20)
 2003/04/17-00:12:47.438532 65.54.240.61.7001 > 192.168.181.71.17767: [|rx]
(20) 
2003/04/17-00:36:44.379117 65.54.240.61.7001 > 192.168.174.69.33837: [|rx]
(20) 
2003/04/17-00:36:47.486838 65.54.240.61.7001 > 192.168.181.71.20202: [|rx]
(20) 
2003/04/17-00:44:09.253133 65.54.240.61.7001 > 192.168.181.71.17746: [|rx]
(20)

----------------------------------------------------------------------------
Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the 
world's premier event for IT and network security experts.  The two-day 
Training features 6 hand-on courses on May 12-13 taught by professionals.  
The two-day Briefings on May 14-15 features 24 top speakers with no vendor 
sales pitches.  Deadline for the best rates is April 25.  Register today to 
ensure your place. http://www.securityfocus.com/BlackHat-incidents 
----------------------------------------------------------------------------


Current thread: