port 22224?? What the heck

From: Gary Baribault (gary@baribault.net)
Date: 01/25/02


Date: Fri, 25 Jan 2002 13:46:52 -0500
To: incidents@securityfocus.com
From: Gary Baribault <gary@baribault.net>

I got a scan last nigh from and to port 22224... Has anyone else seen a
scan like that? Any idea what they are looking for?

[root@ns1 root]# grep 208.1.80.131 /var/log/messages.1
Jan 24 10:38:50 ns1 kernel: Packet log: input REJECT eth1 PROTO=6
xxx.1.80.131:22224 209.71.230.115:22224 L=40 S=0x00 I=19289 F=0x0000 T=109
SYN (#17)
[root@ns1 root]#

Gary Baribault
gary@baribault.net

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Sind das Angriffe?
    ... Matcht das erste TCP SYN Paket an Port 22. ...
    (de.comp.security.firewall)
  • Re: Port 119 Scans
    ... Subject: Port 119 Scans ... > there some sort of news server exploit out? ... I saw a burst one specific day, ... RES=0x00 SYN URGP=0 ...
    (Incidents)
  • Re: Nmap/netwag problem.
    ... Are you suggesting that if I send a Syn to port 80, ... > pass my original Syn if it sees a valid HTTP request following it? ... But the situation it does exist and not just do to the host or a device. ... I think the trade off between efficiency and reliability never came to ...
    (Pen-Test)
  • Re: simple but fast port scanner
    ... I need to do this in a SYN scan mode which is described ... the port is marked as filtered. ... If you want to write one yourself: then read the source code for nmap to see ... unless you can find some sample code which uses raw sockets. ...
    (comp.lang.ruby)
  • Re: is my linux box trojaned by Trinity ?
    ... port but destination port. ... 32770 is Trinity backdoor port but not DDoS attack port. ... >Or are those packed an answer to an SYN request coming from my computer? ... >Those packets came while i was surfing. ...
    (comp.os.linux.security)