UDP port 500 traffic from two clients

From: Chris Wilkes (cwilkes@ladro.com)
Date: 01/28/02


Date: Mon, 28 Jan 2002 08:27:19 -0800
From: Chris Wilkes <cwilkes@ladro.com>
To: incidents@securityfocus.com

I recently moved and changed IP addresses within my ISP's block and two
IP addresses from mediaone.net and home.com hit me a couple of times a
minute with a UDP request to port 500.

Looking around on the net it appears this could be a machine trying to
VPN into mine. Since this is the first time these addresses have shown
up and they are just coming to and from port 500 I think their machines
mine be misconfigured or there is a DNS entry out there that says my
machine is the one that they want to get to.

What's the best way to stop this? I sent an email off to the abuse
address at the two ISPs (I'm sure that will go straight to /dev/null as
they are really large) asking them to investigate, but is there anything
else I should do?

I setup a UDP server to capture the data that they are sending and the
results of the two are at http://ladro.com/udp500.txt . They kept on
repeating the same 219 bytes over and over. The pattern has since
changed, but it looks like it is staying the same.

Right now I'm sending back a UDP packet of "Go away" but I'm wondering
if there is something else I can do. Is there some IKE message that
tells them to give up or one that will send a message to their screen?

Feel free to email me for more details.

Chris

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Block UDP Ports?
    ... I'm using Checkpoint Firewall-1. ... reasonable that Firewall-1 would leave UDP wide open. ... > UDP ICMP port unreachable scanning: This scanning method varies from the ...
    (comp.security.firewalls)
  • UDP DoS attack in Win2k via IKE
    ... This memo should clarify the issue discovered with the UDP DOS ... Sending of UDP traffic to port 500 UDP will cause windows to ... attacked host is an IPSec gateway). ...
    (Bugtraq)
  • Re: LDAP UDP Port Problem
    ... The correct fix is to identify that the network gear is tossing out the UDP ... Then I did some portqry's on the LDAP port ... > Sending LDAP query to TCP port 389... ...
    (microsoft.public.windows.server.networking)
  • Re: Block UDP Ports?
    ... UDP scanning is questionable to many - if the port is open, ... closed ports aren't even required to send an error packet. ...
    (comp.security.firewalls)
  • Re: LDAP UDP Port Problem
    ... The correct fix is to identify that the network gear is tossing out the UDP ... Then I did some portqry's on the LDAP port ... > Sending LDAP query to TCP port 389... ...
    (microsoft.public.windows.server.setup)