Strange connections to ports 1214, 6346 and 28800

From: Jeroen Peters (rump@plasticgirl.com)
Date: 11/02/01


From: "Jeroen Peters" <rump@plasticgirl.com>
To: <incidents@securityfocus.com>
Subject: Strange connections to ports 1214, 6346 and 28800
Date: Fri, 2 Nov 2001 11:10:16 +0100
Message-ID: <000501c16386$9268e540$0300a8c0@judicatorwks>

Hello,

Does anyone know what this could be:

Yesterday, my Internet connection went down. I have a cable modem
connection with an Amsterdam (the Netherlands) provider.
When I did an Ipconfig on the machine connected to the cable modem it
returned 0.0.0.0 for the external NIC. A renew didn't work. (The
external adapter receives it's address by DHCP, which stays normally the
same with every renew)).
Nothing strange so far.
However, when I opened Winroute (which operates as a NAT/Firewall for my
internal network) and took a look at the security log window, it was
going like a madman!
What I saw where lots and lots of connections to OTHER machines from
other machines to TCP port 1214, TCP port 6346 and UDP port 28800. Port
1214 was dominant in numbers. Was I running in promiscuous mode? When I
asked a friend who's on a different subnet with the same provider to
ping one of the targeted machines, his ping showed up in my log!!!!!
At this point, Ipconfig still showed 0.0.0.0 for my external adapter.
After 4 hours the connections seized, and I was able to renew my
external adapter. Strangely, it received a different IP address then
normal (in the same subnet).

A closer look to my log showed the following:

- 3024 unique IP address had connections (attempts?) to 4 unique IP
addresses to TCP port 1214,
- 6 unique IP addresses had connections to UDP port 28800 to 1 unique IP
address,
- 47 unique IP addresses had connections to TCP port 6346 to 1 unique IP
address.
- All targeted machines where in my subnet, the source IP addresses came
from all over the world, dial ups, dot coms, dot edu, dot net etc.
- Non of the above mentioned hosts targeted my machine directly.

Right now, a trace route to the yesterday targeted machines returns
nothing. (normally it would at least show the 10.19.*.* from my cable
modem and upstream routers).

I would love some comments on this,

Regards,

Jeroen Peters

Amsterdam
the Netherlands

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Strange connections to ports 1214, 6346 and 28800
    ... Strange connections to ports 1214, ... Don't know the details of your provider's cable modem network. ... TCP 6346 is the default port for Gnutella, ... > - All targeted machines where in my subnet, ...
    (Incidents)
  • Re: OpenSSH 3.4p1 Trouble on SCO 5.0.5?
    ... connections across the US so I can see 1 hop from Orlando to ... IMO the ONLY machines that should be do so would be machines ... that MUST be connected - eg mail servers and web servers. ... Switching the SSH port to, say, 1022 and making sure there are ...
    (comp.unix.sco.misc)
  • Re: Cannot connect to remote compter, need help troubleshooting
    ... Even ISP's that block port 80 only block it inbound towards subscriber ... So--if the machine to which you are connecting is across the Internet from ... If, in fact, it is your home machine with the new cable modem you are trying ... >> way with outbound connections to another machine. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: OpenSSH 3.4p1 Trouble on SCO 5.0.5?
    ... connections across the US so I can see 1 hop from Orlando to ... I neglected to indicate that the machine is behind a firewall and port ... that MUST be connected - eg mail servers and web servers. ... NIC would go to your business machines on a totally private network ...
    (comp.unix.sco.misc)
  • Port "0" scanning
    ... We are noticing a massive increase in connections from Port "8" on external ... machines to Port "0" on our machine. ... Is there a way to stop ACCEPTing these connections? ... experiencing an overall sluggishness in internet responsiveness in recent ...
    (alt.computer.security)