Re: Port scan from Apache?



On Tuesday, 2006-07-18 at 18:11:50 +0200, Clemens Renner wrote:

[Root]system-alert-00016: Port scan! From $my-server-ip:80 to
$their-server-ip:8254, proto TCP (zone Untrust, int ethernet1). Occurred
1 times.

With IPFilter, I often see "dangling FINs" in the log. These occur when
the TCP connection has been shut down but an additional FIN is still
travelling. IPFilter will have abandoned the state for the connection,
so for it these FIN are not associated to a connection.

Since the message they gave you is of the "Danger, Will Robinson" kind,
this could be the case. They can't prove it wrong.

To me, this is a case of stupid until proven intelligent.

HTH,
Lupe Christoph

PS: I thought a port scan means somebody is probing many ports. How can
one packet be considered a port scan?!?
--
| You know we're sitting on four million pounds of fuel, one nuclear |
| weapon and a thing that has 270,000 moving parts built by the lowest |
| bidder. Makes you feel good, doesn't it? |
| Rockhound in "Armageddon", 1998, about the Space Shuttle |
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Port 29801 25957 ?
    ... Subject: Port 29801 25957? ... port 25957 connection (FIN) attempt from X.X.X.X ... LAST MINUTE: Goraca oferta turystyczna ...
    (Security-Basics)
  • Re: FIN_WAIT_2 and a socket connect that takes an age to close.
    ... But not a FIN from it... ... full-duplex and allows the connection to be closed in a single direction ... But the _peer_ has not done similar: the application there has not done ... Other possibilities are that the peer application has a two minute timeout. ...
    (microsoft.public.win32.programmer.networks)
  • Re: SSL/TCP Connection termination results in RST
    ... A "FIN" means that the connection is being terminated. ... A TCP connection is duplex; with an independent stream in each direction. ... Receiver, and then may send a FIN segment to close its half of the ...
    (comp.dcom.sys.cisco)
  • Re: LoadBalancer With FreeBSD
    ... > You can do Round Robin with Ipfilter. ... > They are just proxy. ... pen work very well. ... > Number of connection is not a big problem with good sysctl value and ...
    (freebsd-isp)
  • =?windows-1252?Q?If_shutdownOutput=28=29_doesn=92t_cause_other_end_to_sta?= =?windows-1252?Q
    ... this case, it should send FIN) ... close the connection. ... close end to start TCP close sequence, why do we then use shutdown ... If client performs active open, but for some reason server doesn’t ...
    (comp.lang.java.programmer)